Prometheus is a Windows ransomware family first observed in February 2021 and widely assessed as a Thanos-derived variant built from leaked Thanos code. It is associated with a double-extortion operation that encrypts victim files while also threatening to leak stolen data through a dedicated extortion site and negotiation portal. The operators publicly claimed links to REvil, but reporting consistently found no technical evidence supporting that affiliation. Victims spanned multiple sectors, with manufacturing and transportation/logistics appearing prominently among observed cases, alongside government, financial, healthcare, energy, legal, consulting, agriculture, and other enterprises across several regions.
Prometheus is implemented as a .NET ransomware strain targeting Windows environments. Across analyses, it has been reported using Salsa20 for file encryption, with some reporting on Prometheus-linked Thanos samples describing AES-based encryption behavior in related campaigns. Prometheus appends victim-specific extensions to encrypted files, drops text and HTA ransom notes, and uses common Thanos-family markers also seen in related variants such as Haron, Spook, and Midas. The malware attempts to maximize encryption success by terminating processes and services associated with backups, databases, office applications, and security tooling, including artifacts related to the Raccine anti-ransomware utility. It has also been observed modifying service configurations and, in some reporting on Prometheus-linked samples, altering firewall or registry settings as part of pre-encryption preparation and defense evasion.
The family is notable for weaknesses identified in some Prometheus encryption implementations. Multiple researchers documented flawed key generation tied to system tick count or uptime, enabling development of decryptors that could recover at least some encrypted files, especially where known file headers or other recoverable parameters were available. These weaknesses distinguished Prometheus from more mature ransomware families whose cryptography generally prevents recovery without attacker-held keys.
Prometheus forms part of a broader cluster of Thanos-based ransomware activity and has been linked genealogically and operationally to later variants including Haron and Spook. Its emergence illustrates how leaked ransomware builders enabled rapid rebranding, customization, and commercialization of extortion operations by multiple actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Prometheus Different Thanos-based Ransomware Prometheus Ransomware "GotAllDone" Ransomware Prometheus NextGen Ransomware Variants, variation, modification: Getin, CGP, Haron (Chaddad), Boooom, Spook, ltnuhr, Steriok, Unlock, ZZZZZZZZZZ, Matilan.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK ... T1486 – Data Encrypted for Impact ... Spook, mirroring the manifestos of others, boasts “very strong (AES) encryption” ... Encryption of a full disk can occur within just a few minutes
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family described as closely related to Spook, with notable code overlap and similar payment portal and ransom note construction.
A Thanos-built ransomware variant that encrypts files, drops RESTORE_FILES_INFO ransom notes, and uses double extortion through a leak site.
Ransomware that encrypts files on infected devices. In this case, its encryption key seed generation used a hardcoded IV and the computer uptime, making decryption feasible under certain conditions.
Ransomware that encrypts files using Salsa20 and a tickcount-based 32-byte visible-character password; the content discusses a decrypt/brute-force utility that attempts to recover the encryption key/seed and decrypt affected files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.