New Prinz Eugen ransomware prioritizes recent files for encryption
ID: d47085ed-5e54-534f-ad8f-e357cb7b131b
STIX ID: report--d47085ed-5e54-534f-ad8f-e357cb7b131b
Feed Name: Bleeping Computer
Threat Score
**Prinz Eugen ransomware** is an active hands-on-keyboard extortion operation that gains initial access via stolen RDP credentials and abuse of legitimate RMM tools (e.g., RemotePC), manually deploys a Go-based payload (servertool.exe), prioritizes encryption of recently modified files, and uses strong cryptography (ChaCha20-Poly1305 with Argon2id/HKDF-SHA256) while leaving no on-disk ransom note; researchers observed multiple victims and provide IOCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
