Many hackers saw the new Covid-19 pandemic as the perfect opportunity to focus on an already overloaded healthcare sector. The ProLock ransomware is another threat added to the list.
The FBI issued an alert earlier this month to alert organizations to the new threat actor, saying its targets in the US include entities in the following sectors: healthcare, government, finance, and retail.

Decryption malfunction
The FBI does not encourage you to succumb to the demands of any hacker. Such a thing would only boost their confidence to continue such attacks.
With ProLock, the decryptor does not work properly and the data will be lost. Files larger than 64MB may be corrupted during the decryption process.
The loss of integrity of 1 byte per 1KB is possible with files over 100MB and may require additional work for the decryptor to function correctly. This issue will increase the downtime of an organization even if they agree to the hacker's demands.
The malware started as PwndLocker in late 2019, but gained notoriety by targeting businesses and local governments, tailoring ransom demands to the size of the compromised network.
After a bug that allowed free decryption was fixed, PwndLocker appeared as ProLocker in March and its activity began to scale up.
Network entry
As highlighted by the cybersecurity company Group-IB in a recent report, ProLock collaborated with the QakBot banking trojan to gain access to victims' networks. This likely contributed to the rise in reputation of this ransomware.
The Trojan does not install this ransomware family, but runs a script to allow the hackers to infiltrate the victims' network, so they can map it and move laterally. The payload is extracted from a BMP or JPG file named WinMgr and is loaded into memory.
Like other ransomware operators, ProLock spends some time on the victim's network searching for high-value systems and important data to steal. The information is sent using Rclone, a command-line tool for syncing with various cloud.
The ransom demand after encryption comes with the threat that the victims' data will be posted on public websites and social media, unless a payment for decryption is made.
Other methods include misconfigured Remote Desktop Protocol (RDP). For networks with single-factor authentication, the hacker uses stolen login credentials.
Once inside, ProLock operators make sure to leave no option for recovering files without payment. If backups and shadow copies are found, they are either deleted or encrypted.
With ransom demands ranging between $175,000 and over $660,000, ProLock is as serious a threat as other, more notorious ransomware families such as Maze, Sodinokibi, Ryuk or LockerGoga , which are considered top workers in the ransomware business.
