ROOTBOY is a cybercriminal operator publicly linked to the Prinz Eugen ransomware operation and to earlier underground sales of stolen data under the aliases GERMANIA and avtokz. Available reporting indicates the activity is likely conducted by a single operator rather than a large intrusion set. The actor has been associated with financially motivated extortion and data monetization, including the sale of large breached datasets and ransomware-backed leak-site pressure. ROOTBOY has been tied to intrusions affecting organizations in the financial sector and other commercial targets across multiple countries, including South Africa, France, the United States, and Canada. Reported victimology includes Standard Bank Group, Transitions Pro Centre Val de Loire, 700Credit, Vantage Finance, and a driving-school software provider serving the US and Canada. In the 700Credit case, ROOTBOY advertised stolen consumer data for sale after a failed extortion attempt attributed to the GERMANIA alias. In ransomware operations attributed to ROOTBOY, initial access has been associated with compromised Remote Desktop Protocol credentials. Post-compromise activity included abuse of legitimate remote management software to launch PowerShell stagers, retrieval of additional payloads assessed as remote-access or infostealing tooling, and creation of a hidden local administrator account for persistence. The actor has demonstrated data theft and exfiltration prior to encryption, followed by extortion through a leak site and out-of-band victim communications rather than reliance on an on-disk ransom note. The Prinz Eugen malware linked to ROOTBOY is a Go-based encryptor engineered for operational impact and anti-forensic effect. It prioritizes recently modified files, recursively encrypts data, uses ChaCha20-Poly1305 with per-file keys derived through a multi-stage key derivation process, and can delete originals after successful encryption. The malware also wipes key material from memory and self-deletes after execution. Reported campaign tradecraft included typosquatted infrastructure and fake CAPTCHA lures, indicating attention to deception and operational security. Overall, ROOTBOY is best characterized as a financially motivated extortion actor combining credential-based intrusion, remote administration abuse, PowerShell-based staging, data theft, ransomware deployment, leak-site coercion, and underground resale of stolen information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Single-operator extortion and ransomware activity associated with the Prinz Eugen campaign, including prior stolen-data sales and breaches, and current ransomware deployment against organizations in multiple countries.
Named actor linked to the Prinz Eugen operation and earlier data-sale/extortion activity, reusing the same handles, TOX ID, and German-themed extortion branding across breaches and leak-site activity.
ROOTBOY is an underground data broker specializing in the sale of large datasets containing sensitive personal information, primarily from US-based financial and credit organizations. The actor is commercially motivated, focusing on rapid resale of stolen data rather than prolonged extortion or ransomware campaigns. ROOTBOY operates across multiple underground forums and uses multiple aliases and communication channels to facilitate sales and build reputation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.