logo

New Prinz Eugen ransomware prioritizes recent files for encryption

ID: d47085ed-5e54-534f-ad8f-e357cb7b131b

STIX ID: report--d47085ed-5e54-534f-ad8f-e357cb7b131b

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: Bill Toulas

...
...

**Prinz Eugen ransomware** is an active hands-on-keyboard extortion operation that gains initial access via stolen RDP credentials and abuse of legitimate RMM tools (e.g., RemotePC), manually deploys a Go-based payload (servertool.exe), prioritizes encryption of recently modified files, and uses strong cryptography (ChaCha20-Poly1305 with Argon2id/HKDF-SHA256) while leaving no on-disk ransom note; researchers observed multiple victims and provide IOCs and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.