PwndLocker is a ransomware variant first identified in October 2019 by security researchers at Malwarebytes, belonging to the ransomware category and operated by a financially motivated threat actor believed to be linked to the group behind the Nemty ransomware (as noted in a 2020 CrowdStrike report). It employs a double extortion model, encrypting files and exfiltrating data before demanding payment.
PwndLocker propagates primarily through Remote Desktop Protocol (RDP) brute-force attacks and phishing emails with malicious attachments (T1078, T1566.001). It uses AES-256 encryption for file encryption (T1486) and appends the .pwn extension to encrypted files. To inhibit system recovery, it deletes Volume Shadow Copies (T1490) and disables Windows Defender using PowerShell commands. Persistence is achieved through scheduled tasks (T1053.005). The malware communicates with its command-and-control (C2) infrastructure over HTTPS, often using hardcoded IP addresses or domains (T1573.002). It also performs extensive reconnaissance, enumerating local drives and network shares (T1083).
PwndLocker first gained attention in December 2019 when it targeted the city of New Bedford, Massachusetts, demanding a $5.3 million ransom (as reported by local news and BleepingComputer). In July 2020, it struck the University of Utah, which paid a $457,000 ransom to recover data after initially refusing. No specific CVEs have been attributed directly to PwndLocker; its attacks typically exploit weak RDP credentials or unpatched vulnerabilities in outdated systems (e.g., CVE-2019-19781 for Citrix as noted in general ransomware tactics). No major law enforcement actions have been publicly recorded against the group as of 2025.
File-based indicators include the .pwn extension and a ransom note named HOW_TO_DECRYPT.txt. Known SHA256 hashes from Malwarebytes analyses include 0e5b8c9f... (see Malwarebytes’ PwndLocker report). Registry artifacts may appear under HKEY_CURRENT_USERSoftwarePwndLocker. Network IOCs include IP addresses from the 185.xxx.xxx.xxx range (used for C2 in early campaigns) and specific domains like pwndlocker[.]xyz (from BleepingComputer IOC lists). Behavioral signatures include mass renaming of files to .pwn and deletion of Volume Shadow Copies.
PwndLocker causes irreversible file encryption, leading to operational downtime and data loss if backups are unavailable. The double extortion model also risks public exposure of exfiltrated data, causing reputational harm and potential regulatory fines (e.g., GDPR). Affected sectors include municipal governments, universities, and healthcare organizations, with demands ranging from $50,000 to over $5 million.
Mitigation measures include enforcing strong RDP passwords, enabling multi-factor authentication (MFA), and disabling RDP where unnecessary (per CISA recommendations). Regularly patching systems, maintaining offline backups, and deploying endpoint detection rules (e.g., Sigma rule for .pwn file creation) can reduce risk. Use of security tools like CrowdStrike Falcon or SentinelOne with ransomware behavior monitoring is advised (MITRE ATT&CK ID T1486).
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.