logo

Prometheus: New Ransomware Group Targets Organizations

ID: 735c11db-d801-5064-8793-398ef5fbd80e

STIX ID: report--735c11db-d801-5064-8793-398ef5fbd80e

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-12

Date Updated: 2026-07-16

...
...

The report details Cyble's analysis of the Prometheus ransomware group (affiliated with REvil) using a heavily obfuscated Thanos .NET ransomware variant: it enumerates processes, starts/stops and reconfigures services, kills backup/antimalware-related processes, modifies firewall/registry settings, performs AES encryption appending unique extensions, and drops ransom notes. The technical write-up includes runtime-obfuscated base64 strings, lists of targeted file extensions and processes, and a comprehensive list of SHA-256 IoCs, and it concludes with mitigation recommendations such as MFA, LAPS, least-privilege, endpoint defenses, and robust backup practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.