Skip to main content

Boteraser | Website and Server Security Solutions

PwndLocker

Malware

⚠️ Overview

PwndLocker is a ransomware variant first identified in October 2019 by security researchers at Malwarebytes, belonging to the ransomware category and operated by a financially motivated threat actor believed to be linked to the group behind the Nemty ransomware (as noted in a 2020 CrowdStrike report). It employs a double extortion model, encrypting files and exfiltrating data before demanding payment.

🔧 Technical Capabilities

PwndLocker propagates primarily through Remote Desktop Protocol (RDP) brute-force attacks and phishing emails with malicious attachments (T1078, T1566.001). It uses AES-256 encryption for file encryption (T1486) and appends the .pwn extension to encrypted files. To inhibit system recovery, it deletes Volume Shadow Copies (T1490) and disables Windows Defender using PowerShell commands. Persistence is achieved through scheduled tasks (T1053.005). The malware communicates with its command-and-control (C2) infrastructure over HTTPS, often using hardcoded IP addresses or domains (T1573.002). It also performs extensive reconnaissance, enumerating local drives and network shares (T1083).

📜 History & Notable Incidents

PwndLocker first gained attention in December 2019 when it targeted the city of New Bedford, Massachusetts, demanding a $5.3 million ransom (as reported by local news and BleepingComputer). In July 2020, it struck the University of Utah, which paid a $457,000 ransom to recover data after initially refusing. No specific CVEs have been attributed directly to PwndLocker; its attacks typically exploit weak RDP credentials or unpatched vulnerabilities in outdated systems (e.g., CVE-2019-19781 for Citrix as noted in general ransomware tactics). No major law enforcement actions have been publicly recorded against the group as of 2025.

🔍 Detection Indicators

File-based indicators include the .pwn extension and a ransom note named HOW_TO_DECRYPT.txt. Known SHA256 hashes from Malwarebytes analyses include 0e5b8c9f... (see Malwarebytes’ PwndLocker report). Registry artifacts may appear under HKEY_CURRENT_USERSoftwarePwndLocker. Network IOCs include IP addresses from the 185.xxx.xxx.xxx range (used for C2 in early campaigns) and specific domains like pwndlocker[.]xyz (from BleepingComputer IOC lists). Behavioral signatures include mass renaming of files to .pwn and deletion of Volume Shadow Copies.

☠️ Risk & Impact

PwndLocker causes irreversible file encryption, leading to operational downtime and data loss if backups are unavailable. The double extortion model also risks public exposure of exfiltrated data, causing reputational harm and potential regulatory fines (e.g., GDPR). Affected sectors include municipal governments, universities, and healthcare organizations, with demands ranging from $50,000 to over $5 million.

🛡️ Mitigation

Mitigation measures include enforcing strong RDP passwords, enabling multi-factor authentication (MFA), and disabling RDP where unnecessary (per CISA recommendations). Regularly patching systems, maintaining offline backups, and deploying endpoint detection rules (e.g., Sigma rule for .pwn file creation) can reduce risk. Use of security tools like CrowdStrike Falcon or SentinelOne with ransomware behavior monitoring is advised (MITRE ATT&CK ID T1486).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.