Prinz Eugen is a newly identified Go-based ransomware family and operation. It encrypts files on victim systems, appending the .prinzeugen extension, and is notable for prioritizing the most recently modified files first rather than using a conventional alphabetical order; when timestamps match, it falls back to alphabetical processing. Researchers assessed this strategy is intended to maximize operational disruption by hitting current work, active documents, open databases, shared-drive updates, cloud-synced files, and other recently changed data before older content.
The malware recursively scans accessible directories without meaningful depth restrictions and, in analyzed samples, attempted to encrypt virtually every file except those already ending in .prinzeugen and temporary working files. It uses ChaCha20-Poly1305 authenticated encryption with per-file random IVs, processes data in 1 MB chunks, performs integrity verification with SHA-256, and uses a multi-stage key derivation chain described as Argon2id, SHA-256, and HKDF-SHA256. Researchers also reported a custom file header containing the magic bytes CHV1. Prinz Eugen supports an optional --delete flag that removes the original file only after verifying that the encrypted copy can be successfully decrypted.
A defining operational characteristic is stealth and anti-forensics. The analyzed samples did not drop a ransom note, create an HTML page, or change the desktop wallpaper, indicating extortion may occur out-of-band via email or dark-web portals. Before exiting, the malware zeroes key material in memory, invokes garbage collection, and self-deletes from disk, including via a timed Windows command. These behaviors reduce forensic recovery opportunities and can delay incident recognition in environments that rely on ransom-note artifacts for escalation.
Observed intrusion activity indicates a hands-on-keyboard, centrally operated campaign rather than ransomware-as-a-service. In investigated incidents, initial access was likely obtained through compromised RDP credentials. Operators manually downloaded and executed the payload, observed as servertool.exe, and abused the legitimate RemotePC remote management tool to launch PowerShell stagers and deploy additional payloads. Persistence was established in at least one case by creating a hidden or backdoor local administrator account using net user admin germania /add. Additional payloads were retrieved from infrastructure including 212.80.7.74, which researchers suspected functioned as a C2 server and likely supported remote access, infostealing, and exfiltration.
The operation has been linked by researchers to the threat actor ROOTBOY, also associated with the aliases GERMANIA and avtokz. Public reporting tied Prinz Eugen to attacks against organizations in multiple countries and sectors, including Standard Bank Group in South Africa and other entities such as regional training and finance-related organizations. Reporting indicates the campaign combines encryption, data theft, leak-site pressure, and extortion, with stolen data in at least one case reportedly released in daily batches after payment was refused. Known infrastructure and indicators mentioned in reporting include the payload hash 686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4, the IP address 212.80.7.74, domains such as stndrdbnk[.]cc, g-captchafestung[.]sbs, and festung-e.duckdns[.]org, and leak-site URLs including prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd[.]onion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A newly identified ransomware group is using remote management software and scripted attack tools to compromise organizations and deploy a sophisticated encryption threat called Prinz Eugen.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
According to the researchers, initial access is likely achieved through stolen RDP credentials... In an investigated incident, the researchers observed the use of the RemotePC RMM tool and a backdoor administrator account that provided persistence.
Threatdown, Malwarebytes’ enterprise cybersecurity arm, found that the Prinz Eugen hackers have a hands-on-keyboard style and prefer to use legitimate remote monitoring and management (RMM) software and living-off-the-land tools.
According to the researchers, initial access is likely achieved through stolen RDP credentials... In an investigated incident, the researchers observed the use of the RemotePC RMM tool and a backdoor administrator account that provided persistence.
We suspect the actor gained a foothold through compromised RDP credentials.
Three domains resolved to the same server, including a typosquat of Standard Bank’s domain and a fake CAPTCHA page likely used to lure victims...
It also supports an optional --delete flag that removes the original only after checking that the encrypted copy can be decrypted... The analyzed sample zeroes key material, runs garbage collection, and deletes itself after execution.
The operation's encryption strategy includes overwriting the encryption key with zeroes and self-deleting to prevent recovery.
According to the researchers, initial access is likely achieved through stolen RDP credentials... In an investigated incident, the researchers observed the use of the RemotePC RMM tool and a backdoor administrator account that provided persistence.
In the environment ThreatDown investigated, the actor used RemotePC to launch PowerShell stagers and deploy additional payloads... RMM sessions outside normal administrative scope, off-hours connections, or activity from accounts without a change ticket should be treated as possible lateral movement signals.
The researchers noticed that when the malware uses the --delete flag to delete the original file after encrypting it, a check occurs to make sure that the file can be decrypted before removing it from the system.
ThreatDown said the ransomware processes files by modification time, starting with the most recently changed files and using alphabetical order only when timestamps match. The ransomware appends the .prinzeugen extension to encrypted files. ThreatDown said the sample uses ChaCha20-Poly1305 encryption, integrity checks, and a custom file header.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based ransomware encryptor that targets the most recently modified files first, appends the .prinzeugen extension, uses ChaCha20-Poly1305 with per-file keys, avoids dropping a ransom note, wipes keys from memory, and self-deletes to hinder forensics.
Go-based ransomware that prioritizes encrypting the most recently modified files first, appends the .prinzeugen extension, uses ChaCha20-Poly1305 with integrity checks and a custom file header, may optionally delete originals after verifying decryptability, does not leave a ransom note on disk, and deletes itself after execution.
Ransomware operated in a centralized, manual intrusion model rather than a ransomware-as-a-service scheme. It may gain initial access via compromised RDP credentials, is manually deployed by operators, prioritizes encryption of the most recently modified files to maximize business disruption, appends the .prinzeugen extension, uses ChaCha20-Poly1305 with supporting cryptographic components including Argon2id, SHA-256, and HKDF-SHA256, and includes anti-forensic behaviors such as zeroing keys in memory and attempting self-deletion.
Go-based ransomware that prioritizes encryption of recently modified files, recursively encrypts nearly all files, appends the .prinzeugen extension, uses ChaCha20-Poly1305 encryption with Argon2id/SHA-256/HKDF-SHA256-based key derivation, can verify decryptability before deleting originals, overwrites keys in memory, self-deletes, and avoids dropping a ransom note by moving communications out-of-band.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.