Threat Actor Profile
Description
PwndLocker is a ransomware that was observed in late 2019 and is reported to have been used to target businesses and local governments/cities. According to one source, ransom amounts demanded as part of PwndLocker activity range from $175k USD to $650k USD depending on the size of the network. PwndLocker attempts to disable a variety of Windows services so that their data can be encrypted. Various processes will also be targeted, such as web browsers and software related to security, backups, and databases. Shadow copies are cleared by the ransomware, and encryption of files occurs once the system has been prepared in this way. Executable files and those that are likely to be important for the system to continue to function appear to be skipped by the ransomware, and a large number of folders mostly related to Microsoft Windows system files are also ignored. As of March 2020, encrypted files have been observed with the added extensions of .key and .pwnd. Ransom notes are dropped in folders where encrypted files are found and also on the user's desktop.
Confidence Score
Tags
First Seen
Unknown
Last Updated
Unknown
Active Status
ActiveCreated
April 29, 2026
Indicators of Compromise
Loading IOCs…
IOC KQL for Sentinel
STIX Data
{'added_date': None,
'client': '2003264@sit.singaporetech.edu.sg',
'description': 'PwndLocker is a ransomware that was observed in late 2019 and '
'is reported to have been used to target businesses and local '
'governments/cities. According to one source, ransom amounts '
'demanded as part of PwndLocker activity range from $175k USD '
'to $650k USD depending on the size of the network. PwndLocker '
'attempts to disable a variety of Windows services so that '
'their data can be encrypted. Various processes will also be '
'targeted, such as web browsers and software related to '
'security, backups, and databases. Shadow copies are cleared '
'by the ransomware, and encryption of files occurs once the '
'system has been prepared in this way. Executable files and '
'those that are likely to be important for the system to '
'continue to function appear to be skipped by the ransomware, '
'and a large number of folders mostly related to Microsoft '
'Windows system files are also ignored. As of March 2020, '
'encrypted files have been observed with the added extensions '
'of .key and .pwnd. Ransom notes are dropped in folders where '
"encrypted files are found and also on the user's desktop.",
'firstseen': '2020-02-23T00:00:00+00:00',
'group': 'prolock',
'has_negotiations': False,
'has_ransomnote': True,
'lastseen': '2020-04-25T00:00:00+00:00',
'locations': [{'available': False,
'fqdn': 'msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion',
'slug': 'http://msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion',
'title': '',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 1,
'tiaras_metadata': {'has_negotiations': False,
'has_ransomnote': True,
'locations': [{'available': False,
'fqdn': 'msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion',
'slug': 'http://msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion',
'title': '',
'type': 'DLS'}],
'negotiation_count': 0,
'ransomnotes_count': 1,
'ransomware_live_group': 'prolock',
'tools': {},
'url': 'https://www.ransomware.live/group/prolock',
'victims': 2,
'vulnerabilities': []},
'tiaras_source': 'ransomware.live',
'tools': {},
'ttps': [],
'url': 'https://www.ransomware.live/group/prolock',
'victims': 2,
'vulnerabilities': []}