logo

New Prinz Eugen Ransomware Prioritizes Recent Files for Encryption

ID: e55edc72-0472-5486-b105-6ad96585b050

STIX ID: report--e55edc72-0472-5486-b105-6ad96585b050

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-06-21

Date Updated: 2026-06-21

Author: John Kevin Hao

...
...

Researchers have identified Prinz Eugen, a Go-based ransomware operation that prioritizes encrypting recently modified files to maximize operational impact. The threat actors use stolen RDP credentials and legitimate remote management tools (notably RemotePC) in hands-on-keyboard intrusions, create backdoor administrator accounts for persistence, do not operate as RaaS, and avoid leaving on-device ransom notes; a few victims are listed on the group's leak site, and enterprises with exposed RDP or inadequate RMM monitoring are at heightened risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.