Be wary of ProLock ransomware

Businesses must be wary of ProLock ransomware and its faulty decryptor, according to SophosLabs recent research for the security industry…
ProLock ransom note

Share this article:

Sean Gallagher, senior threat research, SophosBusinesses must be wary of ProLock ransomware and its faulty decryptor, according to SophosLabs research

Business need to be wary of ProLock, a quirky, destructive ransomware with troubling aftershocks. SophosLabs has provided an in-depth look at this ransomware and its unusual file encryption: it skips files smaller than 8,192 bytes, and starts encrypting larger files after the first 8,192 bytes. The result is files that are partially readable, and partially encrypted. This could contribute to the reason why the decryptor key, the code victims receive after they’ve paid a ransom to get their encrypted data back, actually corrupts the files that were encrypted to begin with – meaning, even if victims pay, there’s a chance their data will be lost or made more expensive to recover.

Even without the ransomware encryption, ProLock can cause a fair amount of economic damage to victims, since it is likely only the final leg of a breach of a targeted network. Organizations can take steps to prevent these types of attacks, including protecting remote network access by putting RDP access behind a virtual private network and using multi-factor authentication for remote access. As with all ransomware threats, maintaining offline backups, and malware protection for both desktops and servers hardens defenses against attacks like ProLock. Up-to-date endpoint protection tools (such as Intercept X with EDR; see story for defenders) can be effective in blunting and stopping the attack.

“Even under the best of circumstances it is hard to recover from a ransomware attack. But, ProLock’s unusual encryption scheme, coupled with a faulty decryptor provided by the attackers to victims who are willing to cooperate and pay the ransom, make recovery that much more difficult,” said Sean Gallagher, senior threat research, Sophos. “The tactics used by ProLock are achingly familiar in the ransomware space: using RDP, phishing or third-party malware to gain remote access, and using native Windows tools to spread their malware. The use of weak steganography to conceal their code and of obfuscated PowerShell scripts to launch it makes detecting these kinds of attacks without strong malware protection difficult at best, and especially so in the midst of a pandemic. Companies have to take a hard look at how they deploy RDP and remote access. Simply adopting two-factor authentication for remote access and putting RDP sessions behind a virtual private network would significantly reduce the potential for attacks like these.”

 

Share this article on LinkedIn.

See more news here.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top