← All ransomware groups

Ransomware group profile · #298 by claimed victims

Prolock ransomware

PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.

Active First seen Feb 2020
2Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
1Countries hit
1Leak-site URLs tracked, 0 online
25 Apr 2020Latest claim recorded

Victimology

Who Prolock claims to have breached, from 2 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Financial Services1
Government & Defense1

Top countries

United States2

Latest claimed victims 2 most recent

VictimSectorCountryClaimed
Diebold Nixdorf (ATM provider) Financial Services US 25 Apr 2020
LaSalle County Government Government & Defense US 23 Feb 2020

All 2 Prolock victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Prolock is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Prolock ransomware still active?
Prolock is tracked as active. The most recent leak-site claim VULONE recorded is dated 25 April 2020.
How many victims has Prolock claimed?
VULONE has recorded 2 leak-site victim claims attributed to Prolock since February 2020, across 1 countries and 2 sectors.
Which industries does Prolock target?
The sectors most often named on the Prolock leak site are Financial Services, Government & Defense.
Which countries are most affected by Prolock?
Most Prolock victims recorded by VULONE are located in United States.
Where does VULONE get Prolock victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].