A few days ago, the FBI issued a second warning to US companies about ProLock ransomware, which steals data from compromised networks before encrypting its victims' systems . The FBI's 20200901-001 alert issued on September 1st follows the FBI's MI-000125-MW alert issued on the same subject on May 4th, 2020.

In the previous alert, the FBI warned companies that the ProLock decryptor was not working properly and that data would be lost, as files larger than 64MB may be corrupted during the decryption process.
ProLock ransomware began operating as PwndLocker in late 2019, targeting both US businesses and local governments. PwndLocker was renamed ProLocker last March after a bug was patched that allowed for free decryption of locked files, and it began to scale its activity by targeting corporate networks again.

The increase in ransomware activity was likely a result of the collaboration with the QakBot banking trojan, which made it much easier to access new victims’ networks. Since March 2020, ProLock ransomware operators have been extracting information from their victims’ devices before deploying payloads . ProLock ransomware operators then use the stolen data as a means to convince victim organizations to pay ransoms that start at $175,000 and can reach over $660,000, depending on the size of the compromised network.
So far, ProLock has successfully encrypted the networks of organizations around the world, from various industry sectors, including healthcare, construction, finance, and law, including U.S.. ProLock operators have used various methods to compromise their victims' systems, including phishing emailscontaining malicious QakBot attachments, using stolen credentials , and exploiting configuration flaws in the targets' systems.
Malicious actors were observed archiving the stolen data and uploading it to cloud storage platforms, such as OneDrive, Google Drive , and Mega, with the help of the Rclone cloud storage sync command-line tool.

The FBI recommends that organizations affected by ProLock ransomware attacks not pay the ransom demanded of them, as doing so will encourage the ransomware gang to target other victims and, even more, will fund their future illegal “operations.”.
However, the FBI recognizes the damage organizations could face following such attacks and urges victims to report the attacks immediately once their systems are infected with ProLock ransomware, regardless of their decision to pay for a decryptor or not.

Also, reporting the attack to the FBI to provide information related to it, such as phishing emails, recovered ransomware samples, ransom notes, and network traffic logs, could help prevent other attacks, as well as identify the attackers.
Additionally, the FBI recommends that U.S. organizations back up their data periodically to an off-line/off-site backup location and always keep software to fix any security flaws discovered by ProLock operators. Finally, organizations are advised to implement two-factor authentication (2FA) and disable unused RDP instances as well as automatic attachment downloads in email clients.
