Prestige ransomware is a Windows ransomware family first observed in October 2022 during attacks against transportation, logistics, and other organizations in Ukraine and Poland. It is a 32-bit Windows executable written in C/C++ that encrypts victim files and appends a new extension to affected data. The malware uses embedded cryptographic material, including a hardcoded RSA public key and references to Crypto++ as well as AES and DES, enabling file encryption without requiring network connectivity.
During execution, Prestige enumerates files, directories, processes, and system information, and modifies the Windows registry. It establishes a custom file association for encrypted files so that opening them displays the ransom note through a standard text editor. It also attempts to impair recovery by deleting backup catalogs and volume shadow copies, and it can stop services such as Microsoft SQL Server prior to encryption. Observed behavior indicates it encrypts data on the compromised host but did not demonstrate autonomous propagation across reachable shared folders in testing.
Prestige has been associated with intrusions in which attackers had already obtained privileged credentials before ransomware deployment, indicating use as a late-stage payload in broader post-compromise operations rather than as a self-spreading worm. Reporting has noted overlap in victimology with earlier disruptive activity affecting Ukrainian organizations, including some entities previously targeted by HermeticWiper, but no confirmed attribution to a specific threat actor or established ransomware group was available at the time of reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Windows WMI Process And Service List ... T1047 ... Windows Post-Exploitation, Prestige Ransomware
Threat actors possibly used remote code execution tools and schedule the activities to run the payload on target systems.
Threat actors possibly used remote code execution tools and schedule the activities to run the payload on target systems.
Prestige Ransomware uses reg.exe commands to register a custom file extension handler for files with .enc file extension.
Mitre ATT&CK Tactics and Techniques Sr.no Tactics Technique ID ... T1070.004: Indicator Removal on Host: File Deletion
Related Detections ... Dump LSASS via procdump ... Creation of lsass Dump with Taskmgr ... Access LSASS Memory for Dump Creation ... Detect Credential Dumping through LSASS access ... Dump LSASS via comsvcs DLL ... Windows Credential Dumping LSASS Memory Createdump ... Windows Possible Credential Dumping
Windows Cached Domain Credentials Reg Query ... Anomaly Endpoint T1003.005 Windows Post-Exploitation, Prestige Ransomware
Windows Credentials in Registry Reg Query ... Anomaly Endpoint T1552.002 Windows Post-Exploitation, Prestige Ransomware
Windows Private Keys Discovery ... Anomaly Endpoint T1552.004 Windows Post-Exploitation, Prestige Ransomware
Windows Credentials from Password Stores Query ... Anomaly Endpoint T1555 Windows Post-Exploitation, Prestige Ransomware, DarkGate Malware, NetSupport RMM Tool Abuse
Mitre ATT&CK Tactics and Techniques Sr.no Tactics Technique ID ... T1012: Query Registry
Windows System Network Config Discovery Display DNS ... Anomaly Endpoint T1016 Medusa Ransomware, Windows Post-Exploitation, Prestige Ransomware, Water Gamayun
Windows System User Discovery Via Quser ... Hunting Endpoint T1033 Prestige Ransomware, Crypto Stealer, Windows Post-Exploitation
Windows System Network Connections Discovery Netsh ... Anomaly Endpoint T1049 Windows Post-Exploitation, Prestige Ransomware, Snake Keylogger
The Prestige Ransomware has the following capabilities Gathering System Information. Enumerating through directories, files, and processes.
The Prestige Ransomware has the following capabilities Gathering System Information.
Prestige Ransomware traverses the directories, files, and processes to encrypt the content of files that have one of the hardcoded file extensions.
Prestige Ransomware sample which Enumerates the directories/files and encrypts the victim’s specific files by renaming them to “.enc” file extension.
Prestige Ransomware attempts to stop the MSSQL Windows service before encrypting the files using the net.exe command.
Prestige Ransomware runs the following command to delete the backup catalog from the system: – C:\Windows\System32\wbadmin.exe delete catalog -quiet Prestige Ransomware also runs the following command to delete volume shadow copies on the system: – C:\Windows\System32\vssadmin.exe delete shadows /all /quiet
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated Analytic Story Azorult ... Crypto Stealer ... Prestige Ransomware ... XMRig
Associated Analytic Story Active Directory Lateral Movement ... NOBELIUM Group ... Phemedrone Stealer ... Prestige Ransomware ... Quasar RAT ... RedLine Stealer ... Scheduled Tasks
Associated Analytic Story Data Destruction Hermetic Wiper Prestige Ransomware Windows Persistence Techniques Windows Privilege Escalation Windows Registry Abuse
Ransomware that enumerates directories, files, and processes; encrypts victim files by appending the .enc extension; drops a ransom note at C:\Users\Public\README; registers a custom file extension handler to display the ransom note; deletes volume shadow copies and backup catalogs; and can encrypt files offline using a hardcoded RSA public key with references to AES and DES.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.