logo

Hackers Use RemotePC RMM and PowerShell Stagers to Deploy Prinz Eugen Ransomware

ID: 1858b93c-6c82-5389-a7b3-9891f05fc57f

STIX ID: report--1858b93c-6c82-5389-a7b3-9891f05fc57f

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Tushar Subhra Dutta

...
...

A newly observed ransomware campaign called Prinz Eugen (first seen April 16, 2026) is operated by an actor known as ROOTBOY/GERMANIA and leverages compromised RDP credentials, abused RemotePC RMM, and PowerShell stagers to deploy a Go-based encryptor that uses ChaCha20-Poly1305 with per-file keys and strong anti-forensic cleanup; the report details active extortion against multiple victims (including Standard Bank), provides technical analysis and IoCs (IP 212.80.7.74, domains, file hash, BTC address, emails, and file markers), and recommends monitoring for unauthorized RMM use, PowerShell execution, and new local admin accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.