Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers identified a campaign impersonating the British postal carrier Royal Mail delivering Prince ransomware. Prince is a ransomware variant freely available on GitHub with a “disclaimer” that it is only designed for educational purposes.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Used PowerShell to create a Scheduled Task that ran every 20 minutes, but only if the computer was connected to power and had been idle for 15 minutes
It used PowerShell to run PS1.ps1 and PS2.ps1... JS2.js again ran the PS1.ps1 AMSI Bypass, and then ran PS3.ps1... The Scheduled Task ran an encoded PowerShell command
It used the “findstr” command to find the JavaScript code embedded in the shortcut, wrote it to a file... in %temp%, and executed it using WScript.
Used PowerShell to create a Scheduled Task that ran every 20 minutes, but only if the computer was connected to power and had been idle for 15 minutes
Deleted all previously dropped files Wrote three Base64 strings to the registry (keys varied between the scripts)
The second ZIP file contained a shortcut (LNK) file which, if executed, extracted and ran JavaScript extracted from the shortcut itself... It used the “findstr” command to find the JavaScript code embedded in the shortcut, wrote it to a file... and executed it using WScript.
Used PowerShell to create a Scheduled Task that ran every 20 minutes, but only if the computer was connected to power and had been idle for 15 minutes
The second ZIP file contained a shortcut (LNK) file which, if executed, extracted and ran JavaScript extracted from the shortcut itself... It used the “findstr” command to find the JavaScript code embedded in the shortcut, wrote it to a file... and executed it using WScript.
The JavaScript, which is heavily obfuscated... PS1.ps1 was a highly obfuscated version of a well-known AMSI Bypass... PS2.ps1 was a highly obfuscated version of a well-documented Windows Connection Manager UAC bypass... PS3.ps1, which was again heavily obfuscated... The loaded .NET assembly... was likely obfuscated with some form of the ConfuserEx obfuscator
The emails all contained a sender or reply-to Proton Mail email address... Email lure impersonating Royal Mail... Messages contained a unique PDF attachment that also impersonated Royal Mail.
Created an AES decrypt function that used the AES key and Initialization Vector from the previously written registry keys... decrypted the third Base64 encoded registry key, decoded the resulting Base64, which was compressed with Gzip, and extracted that data to a new Base64 string. This final string was decoded to bytes and loaded as a .NET assembly.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An open-source Go-based ransomware builder used to generate ransomware variants. It uses ChaCha20 and ECIES for file encryption and allows customization of file extensions and ransom notes through a configuration file.
Open-source ransomware builder available on GitHub. In this campaign it was delivered via Royal Mail-themed lures, ultimately loading a .NET assembly built with Prince Ransomware. It encrypted files, appended the ".womp" extension, displayed a fake Windows Update screen, changed the desktop background, and dropped a ransom note. The report states there was no observed data exfiltration or practical decryption workflow, making the attack effectively destructive.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.