ProLock is a financially motivated ransomware operation that compromises corporate networks and encrypts victim data to demand ransom payments. Its operators partnered with distributors of QakBot, also known as QBot, to obtain initial access to corporate networks and deliver ransomware following infection. ProLock can delete Windows Volume Shadow Copies using the native Volume Shadow Copy administration utility, inhibiting recovery of encrypted data. QakBot distributors subsequently shifted from delivering ProLock to delivering Egregor; this delivery relationship does not establish that the two ransomware operations are the same actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
27 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a ransomware group that used QakBot for initial infection. The listed groups are collectively associated with damage to businesses, healthcare providers, and government agencies; no ProLock-specific incident is described.
Ransomware group identified as using Qakbot for initial access in attacks that extort victims for bitcoin ransom payments.
Named as one of several ransomware groups that used Qakbot for initial access before conducting extortion and ransom operations.
Mentioned as a past ransomware operation that partnered with QBot distributors for network access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.