Prometheus emerged as a Thanos-based ransomware operation targeting organizations with file encryption, victim-specific extensions, and ransom notes such as RESTORE_FILES_INFO.txt and .hta variants, while also threatening to leak stolen data through a dedicated extortion site and negotiation portal. Researchers said the group claimed ties to REvil, but multiple analyses found no technical evidence to support that assertion, instead linking Prometheus to the leaked Thanos builder and a broader ransomware-as-a-service ecosystem. Reported demands ranged from $6,000 to $100,000 in Monero, and the malware was observed terminating backup and security processes, altering services, and disabling protections including Raccine to speed encryption and increase pressure on victims.
A free CyCraft decryptor later offered partial recovery for some Prometheus-encrypted files by brute-forcing the malware's weak tickcount-derived Salsa20 key generation, a flaw that made decryption feasible when known file structures or magic bytes were available. Its release was followed by the apparent shutdown of Prometheus infrastructure, but closely related Thanos-derived strains including Haron, Spook, and Midas continued to appear, reusing code, extortion tactics, leak sites, and technical markers such as shared note formats and encryption artifacts. Subsequent reporting tied these families to rebranding and builder reuse rather than a single clear attribution, showing how Prometheus became part of a wider lineage of ransomware operations targeting businesses across multiple sectors and countries.

TTPs, infrastructure, and targeting history in one profile.
17 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz investigated a January 2022 report that Midas had been deployed slowly over a two-month period. The intrusion reportedly involved PowerShell scripts, remote access tools, and an open-source Windows utility.
A .NET Spook sample with SHA1 a63a5de26582af1438c9886cfb15c4baa08cce2e was first seen on VirusTotal on 02 October. SentinelOne later analyzed the sample as part of its Spook reporting.
Midas emerged in October 2021 as another Thanos-family ransomware variant using double extortion and its own leak site. Later analysis noted overlap between Midas and previously inactive Haron victim data.
The public Spook leak blog went live in early October 2021. At the time of reporting, the site listed 17 victims and was described as publishing victims regardless of whether they paid.
Spook ransomware was first seen in late September 2021 as another Thanos/Prometheus-related extortion operation. Researchers described it as using encryption, data leak threats, and additional coercive tactics.
July 13 was also the last date on which the Prometheus gang published content on its dark web leak site. Subsequent reporting linked this date to the apparent winding down of the operation.
CyCraft released a free Prometheus decryptor on GitHub that brute-forces the ransomware's tickcount-based Salsa20 key generation to recover some encrypted files. Reporting noted the tool was mainly effective for smaller files.
Unit 42 reported that Prometheus used a customized Thanos variant, operated leak and negotiation portals, and claimed 30 victims across industries and regions. The researchers found no evidence supporting the gang's claimed affiliation with REvil and assessed the claim may have been reputational pressure or a false flag.
Cyble reported that the Prometheus group had resumed activity and was operating a dark web blog while claiming affiliation with REvil. Its analysis tied recent attacks to a modified, obfuscated Thanos sample used by the group.
Prometheus was first observed in February 2021 as a Thanos-derived ransomware operation using double extortion. Researchers later described it as an emerging gang that quickly scaled victimization across multiple sectors and countries.
Thanos ransomware was first identified in February 2020 as a ransomware-as-a-service offering advertised on the dark web. Later reporting described it as a C#/.NET builder that enabled customized ransomware variants.
A 29 September 2021 variant was likely named Spook Ransomware and used the extension .PUUEQS8AEJ. The sample MD5 was reported as 537a415bcc0f3396f5f37cb3c1831f87.
About two and a half weeks after July 13, Prometheus appeared to have ceased operations. This apparent shutdown was noted alongside the emergence of Haron as another Thanos-based group.
A variant dated 17 July 2021 identified itself on its Tor site as Haron Ransomware and used the .chaddad extension. Later reporting described Haron as a newly discovered Thanos-derived variant that emerged after Prometheus went quiet, prompting rebrand speculation.
A variant dated 16 July 2021 used the .CGP extension, the file name cgpshare.exe, the email yourdata@RecoveryGroup.at, and the URL supportdatarecovery.cc. The sample MD5 was reported as e8f8e4eb0d2c03f0b12fb1cf09932bbd.
A Prometheus variant dated 14 June 2021 used the .getin extension, the ransom note RESTORE_FILES_INFO.txt, and the email Tiberiano@aol.com. The article states that affected files from this variant were decrypted.
Reports of Prometheus infections began appearing in late April to early May 2021, including victims in multiple countries and sectors. The write-up cites examples such as Ghana National Gas, a cardiovascular center in Tulsa, and Nyack Hotel in New York.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 99 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcezscaler.com
Open sourcesecurityintelligence.com
Open sourcemedium.com
Open sourceblog.cyble.com
Open sourceid-ransomware.blogspot.com
Open sourceattack.mitre.org
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.