Prinz Eugen, also styled PrinzEugen, is an emerging criminal ransomware and extortion operation first observed in 2026. It is assessed as a non-RaaS actor that conducts hands-on-keyboard intrusions rather than relying on broad automated deployment or affiliate-driven operations. The group has been associated with double-extortion activity, combining data theft with selective encryption and leak-site pressure, while in some cases omitting an on-host ransom note and handling extortion communications out of band. Observed tradecraft indicates initial access through compromised remote access credentials, especially RDP, with additional reporting linking the actor to credential abuse, brute-force activity, and exploitation of exposed remote services or internet-facing assets. After access, operators have used legitimate remote monitoring and management software, PowerShell-based staging, living-off-the-land techniques, manual reconnaissance, and persistence through administrator account creation. Post-compromise activity includes Active Directory enumeration, identification of privileged accounts, mapping of sensitive repositories and backup infrastructure, staged archive creation, and exfiltration over encrypted channels. The ransomware itself is a Go-based encryptor that prioritizes recently modified files to maximize operational disruption. It uses ChaCha20-Poly1305 for file encryption and has been reported to recursively process files with minimal exclusions. Anti-recovery and anti-forensic behavior includes overwriting key material in memory, forcing garbage collection, and self-deletion after execution. Researchers have also reported that the malware can verify decryptability before deleting originals in certain execution modes. Prinz Eugen has operated dedicated leak infrastructure and has publicly claimed victims in multiple countries. Reported victimology includes organizations in the United States, South Africa, France, and Canada, with targeting described as favoring banks, public institutions, and service-oriented organizations where reputational pressure can amplify extortion leverage. Known aliases and related naming include prinzeugen, prinz_eugen, and prinz_eugen_group. Separate reporting has also publicly linked Prinz Eugen activity to the criminal persona ROOTBOY, also known as avtokz, and to the extortion alias GERMANIA, though subgroup structure is not established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Newly emerged ransomware/extortion group noted in June 2026.
Named as the ransomware group responsible for the attack and leak post against a US-based organization.
Conducting a ransomware attack and claiming a data breach against a U.S.-based organization.
Ransomware operation using a hands-on-keyboard intrusion model, likely gaining initial access via compromised RDP credentials, manually executing a payload named servertool.exe, prioritizing recently modified files for encryption, and avoiding ransom notes to reduce forensic artifacts and hinder automated extortion-phase detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.