A new ransomware strain called 'Prinz Eugen' has been discovered, written in Go and notable for prioritizing recently modified files during encryption to maximize business impact. It uses ChaCha20-Poly1305 encryption with Argon2id-based key derivation, processes files in 1 MB chunks, and securely wipes its encryption key from memory after use. Unlike typical ransomware, it drops no ransom note on the system, instead conducting extortion communications out-of-band via email or dark-web portals to reduce forensic artifacts. It is not a RaaS operation and gains initial access via stolen RDP credentials, using legitimate RMM tools for persistence. At least five victims have been identified, including Standard Bank, which refused a 1 BTC ransom demand.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Encryption strategyRelated Articles:
430 Impressions