However, it had a vulnerability which researchers were quick to spot and develop a decryptor. Hence, it potentially saved the victims from paying the ransom to recover the data.
Nonetheless, the malware developers have now fixed the bug that made decryption possible. And so, we now have the ProLock ransomware in the wild.
According to BleepingComputer, ProLock largely works in the same way as PwndLocker. However, it encrypts the files while adding the extension .proLock to the file name. Whereas, the high demand for ransom remains the same.
https://twitter.com/AltShiftPrtScn/status/1239966261313847298
- AltShiftPrtScn
Though, it is presently unclear how the attackers manage to place this file on the target device.
So, the ransomware again becomes a real threat for the businesses, with presently no alternate option to escape ransom payments. The only measure to combat such situations is to ensure a robust backup of the data.they targeted a handful of servers. Not sure how they got in (yet) but I can see quite a few keygens and cracking tools on the network, probably just end up being an exposed RDP though :-)
— PeterM (@AltShiftPrtScn) March 17, 2020
Let us know your thoughts in the comments.