Uptime Hamster: 10d 7h 30mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Proton Ransomware

Proton Ransomware

0 incidentes 0 paises 0 sectores ransomware Global Ultimo: -
Aliases: Proton Locker
Ver en IntelTracker → APTTrail →
Proton Ransomware is a financially motivated cybercriminal group that emerged in March 2023, primarily targeting Windows systems to encrypt files and demand ransom. The group has undergone several iterations and rebranding, introducing new variants such as Zola, Shinra, Ripa, Cipher, Limba, and Matrix. While initial samples utilized ECC and AES-GCM encryption, later variants, starting in September 2023, switched to ChaCha20. The group is assessed with moderate confidence to be of Iranian origin, partly due to the Zola variant's inclusion of a kill switch that checks for a Persian keyboard layout. Proton Ransomware distinguishes itself by employing a dual extortion model, encrypting victim files and threatening to leak stolen sensitive data, and has been observed using misleading ransom notes that may claim older encryption algorithms despite implementing newer ones. It should not be confused with the unrelated PrOToN/Xorist ransomware.

Aliases del actor

Proton Locker

Actores similares

tridentlockerransomware · 6avoslockerransomware · 3chilelockerransomware · 3GDLockerSecransomware · 2adminlockerransomware · 2bluelockerransomware · 2dagonlockerransomware · 2flockerransomware · 2qlockerransomware · 2ragnarlockerransomware · 2
Tecnicas MITRE
T1566.001, T1059.001, T1133, T1190, T1486, T1078
Tipo
ransomware
Pais origen
Global
Motivacion
-
Impacto
67
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

AustraliaBulgariaBrazilChinaGermanyEstoniaSpainFranceUnited KingdomHong Kong

Sectores objetivo (SOCRadar)

Software PublishersEnterprises & HoldingAir TransportationManufacturingPublic AdministrationEducational ServicesWholesale TradeInsurancePublishing ServicesTelecommunications