Prinz Eugen is a Go-based ransomware family associated with a hands-on-keyboard extortion operation that appears to be centrally run rather than offered as ransomware-as-a-service. Intrusions linked to this malware have been associated with compromised Remote Desktop Protocol access, abuse of legitimate remote management software such as RemotePC, and PowerShell-based staging activity. Reporting has also linked the operation to the threat actor ROOTBOY, including the aliases GERMANIA and avtokz, and to leak-site-based extortion in which stolen data may be used to pressure victims outside the victim environment rather than through an on-disk ransom note.
A defining characteristic of Prinz Eugen is its file-selection logic: it prioritizes encryption of the most recently modified files before older data, using alphabetical order only to break timestamp ties. This behavior is designed to maximize immediate operational disruption by targeting current work product, recently updated shared data, active documents, and other fresh business-critical content first. The malware recursively traverses accessible directories, attempts to encrypt nearly all reachable files except those already bearing its encrypted extension, and appends a dedicated extension to encrypted data.
Technical analysis has described Prinz Eugen as using ChaCha20-Poly1305 authenticated encryption with per-file randomness and a multi-stage key derivation chain involving Argon2id, SHA-256, and HKDF-SHA256. It processes data in chunks, performs integrity verification, and supports an optional mode that deletes original files only after confirming the encrypted copy can be successfully decrypted. The malware also exhibits anti-forensic and anti-recovery behavior by zeroing key material in memory, invoking garbage collection, and deleting itself after execution. Analysts have noted that examined samples did not drop a ransom note, create an HTML instruction page, or change the desktop wallpaper, indicating that extortion communications may occur through external channels such as leak portals or direct contact.
Observed intrusions indicate that operators use legitimate administration tools and built-in system utilities during post-compromise activity, including payload deployment and persistence establishment through creation of an administrator account. Victimology has included organizations in multiple countries, including financial and other enterprise targets. The combination of manual intrusion activity, data theft, stealthy encryption, and out-of-band extortion makes Prinz Eugen a disruptive ransomware threat with strong emphasis on operational pressure and reduced forensic recoverability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A newly identified ransomware group is using remote management software and scripted attack tools to compromise organizations and deploy a sophisticated encryption threat called Prinz Eugen.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
According to the researchers, initial access is likely achieved through stolen RDP credentials... In an investigated incident, the researchers observed the use of the RemotePC RMM tool and a backdoor administrator account that provided persistence.
Threatdown, Malwarebytes’ enterprise cybersecurity arm, found that the Prinz Eugen hackers have a hands-on-keyboard style and prefer to use legitimate remote monitoring and management (RMM) software and living-off-the-land tools.
According to the researchers, initial access is likely achieved through stolen RDP credentials... In an investigated incident, the researchers observed the use of the RemotePC RMM tool and a backdoor administrator account that provided persistence.
We suspect the actor gained a foothold through compromised RDP credentials.
Three domains resolved to the same server, including a typosquat of Standard Bank’s domain and a fake CAPTCHA page likely used to lure victims...
It also supports an optional --delete flag that removes the original only after checking that the encrypted copy can be decrypted... The analyzed sample zeroes key material, runs garbage collection, and deletes itself after execution.
The operation's encryption strategy includes overwriting the encryption key with zeroes and self-deleting to prevent recovery.
According to the researchers, initial access is likely achieved through stolen RDP credentials... In an investigated incident, the researchers observed the use of the RemotePC RMM tool and a backdoor administrator account that provided persistence.
In the environment ThreatDown investigated, the actor used RemotePC to launch PowerShell stagers and deploy additional payloads... RMM sessions outside normal administrative scope, off-hours connections, or activity from accounts without a change ticket should be treated as possible lateral movement signals.
The researchers noticed that when the malware uses the --delete flag to delete the original file after encrypting it, a check occurs to make sure that the file can be decrypted before removing it from the system.
ThreatDown said the ransomware processes files by modification time, starting with the most recently changed files and using alphabetical order only when timestamps match. The ransomware appends the .prinzeugen extension to encrypted files. ThreatDown said the sample uses ChaCha20-Poly1305 encryption, integrity checks, and a custom file header.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as another ransomware example in recovery guidance.
A Go-based ransomware encryptor that targets the most recently modified files first, appends the .prinzeugen extension, uses ChaCha20-Poly1305 with per-file keys, avoids dropping a ransom note, wipes keys from memory, and self-deletes to hinder forensics.
Go-based ransomware that prioritizes encrypting the most recently modified files first, appends the .prinzeugen extension, uses ChaCha20-Poly1305 with integrity checks and a custom file header, may optionally delete originals after verifying decryptability, does not leave a ransom note on disk, and deletes itself after execution.
Ransomware operated in a centralized, manual intrusion model rather than a ransomware-as-a-service scheme. It may gain initial access via compromised RDP credentials, is manually deployed by operators, prioritizes encryption of the most recently modified files to maximize business disruption, appends the .prinzeugen extension, uses ChaCha20-Poly1305 with supporting cryptographic components including Argon2id, SHA-256, and HKDF-SHA256, and includes anti-forensic behaviors such as zeroing keys in memory and attempting self-deletion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.