ProLock

S0654

Malware.View on attack.mitre.org

About this malware

ProLock is a ransomware strain that has been used in Big Game Hunting (BGH) operations since at least 2020, often obtaining initial access with QakBot. ProLock is the successor to PwndLocker ransomware which was found to contain a bug allowing decryption without ransom payment in 2019.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1027.003
Steganography

ProLock can use .jpg and .bmp files to store its payload.

T1047
Windows Management Instrumentation

ProLock can use WMIC to execute scripts on targeted hosts.

T1068
Exploitation for Privilege Escalation

ProLock can use CVE-2019-0859 to escalate privileges on a compromised host.

T1070.004
File Deletion

ProLock can remove files containing its payload after they are executed.

T1197
BITS Jobs

ProLock can use BITS jobs to download its malicious payload.

T1486
Data Encrypted for Impact

ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024.

T1490
Inhibit System Recovery

ProLock can use vssadmin.exe to remove volume shadow copies.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Group IB Ransomware September 2020 Open source
    Group IB. (2020, September). LOCK LIKE A PRO. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.