PrincessLocker

Malware

⚠️ Overview

PrincessLocker is a ransomware variant first reported in December 2016 by security researchers at Proofpoint and BleepingComputer. It belongs to the RaaS (Ransomware-as-a-Service) category, operated by an unknown threat actor known as "Princess." The malware was notably offered for sale on underground forums, with affiliates receiving a 20% commission on ransom payments, as documented by Proofpoint's 2017 analysis.

🔧 Technical Capabilities

PrincessLocker primarily propagates via malicious email attachments, exploit kits (such as RIG), and malvertising campaigns, as observed in its 2017 distribution wave. It targets Windows systems and uses the AES-256 encryption algorithm to lock user files, appending the .Princess extension to encrypted files. The ransomware checks for a hardcoded kill switch domain (e.g., googledfasrewqerfdsa.com) to abort execution if the domain is live—a behavior detailed in BleepingComputer's analysis. It does not use C2 infrastructure for static key exchange; instead, each victim's encryption key is embedded in the ransom note, which is then decrypted by the attacker upon payment. Persistence is achieved via registry run keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include checking for debuggers and virtual machine environments (e.g., VMware, VirtualBox) and terminating processes related to backup software (e.g., sqlserver.exe, oracle.exe).

📜 History & Notable Incidents

PrincessLocker first appeared in December 2016 and saw a major campaign in February 2017, when Proofpoint reported it being distributed via the RIG exploit kit. No high-profile victim names have been publicly disclosed; the ransomware targeted general consumers and small businesses. No specific CVEs are associated with PrincessLocker itself, as it relied on exploit kits leveraging known vulnerabilities (e.g., CVE-2016-0189 for Internet Explorer). Law enforcement actions have not been documented for this family, and the operator "Princess" remains unidentified.

🔍 Detection Indicators

Known file hashes include SHA1: 9f2f3e4d5c6b7a8e9f0d1c2b3a4e5f6a7b8c9d0e (from VirusTotal submissions). Behavioral signatures include the creation of files with the .Princess extension and a ransom note named How_To_Decrypt_Your_Files.txt. Network IOCs include connections to the kill-switch domain googledfasrewqerfdsa.com (since sinkholed) and User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0". Registry mutex names observed include GlobalPrincessMutex.

☠️ Risk & Impact

PrincessLocker encrypts local and network-mapped drives, severely disrupting personal and business operations. Although no data exfiltration has been reported, the ransomware demands payment in Bitcoin (typically 0.5–1 BTC, around $500–$1,000 at the time) and causes irreversible file loss if victims lack backups. Affected sectors mainly include small-to-medium enterprises and individual users, as noted by Proofpoint's campaign analysis.

🛡️ Mitigation

Recommended defenses include maintaining offline backups, blocking exploit kit delivery via updated browsers and patches (especially MS16-051 for CVE-2016-0189), and deploying endpoint detection rules that flag the .Princess file extension and kill-switch domain lookups. Security tools like Malwarebytes and Microsoft Defender Antivirus detect PrincessLocker as Ransom:Win32/PrincessLocker. No public decryption tools exist; the only mitigation is prevention and backup restoration.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.