Researchers say a new ransomware group called Prinz Eugen is breaking into organizations and encrypting their newest or most recently changed files first to increase pressure to pay. ThreatDown says the operators appear to use stolen Remote Desktop Protocol (RDP) credentials, legitimate remote monitoring and management tools such as RemotePC, and hands-on-keyboard activity. The Go-based encryptor uses ChaCha20-Poly1305, appends a .prinzeugen extension, may delete originals after verifying decryption works, and currently shows at least several known victims, including a reported Standard Bank incident.
Why it matters: Organizations with exposed or weakly protected remote access are at risk, especially if attackers can reuse stolen credentials and blend in with legitimate admin tools. Defenders should review RDP exposure, audit remote-management tool use, hunt for the listed indicators of compromise, and watch for unusual admin account creation.
Bill Toulas
2026.06.20
100% relevant
This article appears to be the first tracked item focused on the Prinz Eugen ransomware operation itself, including its access methods, malware design, and known victim details.
← Back to all stories