ProLocker Ransomware
ProLocker is ransomware first observed in late 2019 that has targeted local government authorities. Previously known as PwndLocker, it was renamed after its creators altered it to prevent free decryption of affected files.
Summary
ProLocker is ransomware first observed in late 2019 that has targeted local government authorities. Previously known as PwndLocker, it was renamed after its creators altered it to prevent free decryption of affected files.
Affected platforms
The following platforms are known to be affected:
Threat details
Attacks using ProLocker are initiated either through a previous Qakbot infection, with Qakbot acting as a backdoor, or via direct access using exposed or insecure RDP connections. Attacks over RDP will commence once ProLocker's operators gather sufficient information to allow ProLocker to propagate across the network, with ProLocker itself being installed using WMIC. During this time, the operators will attempt to extract sensitive information to later be sold or leveraged against victims.
Once access has been achieved, ProLocker will attempt to terminate range of security and database processes before deleting Volume Shadow Copies to hinder file recovery. it then encrypts all local and network non-system files using an unknown algorithm.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files the logged-in user has permission to modify, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 29 June 2021 12:01 pm