Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Prinz Eugen ransomware: a deep dive into a new Go-based encryptor

0
Medium
Published: 06/25/2026 (06/25/2026, 14:55:43 UTC)
Source: AlienVault OTX General

Description

Prinz Eugen is a newly discovered Go-based ransomware family first observed in April 2026, attributed to an actor known as ROOTBOY. The encryptor employs sophisticated techniques including ChaCha20-Poly1305 encryption, prioritizes recently modified files to maximize pressure on victims, and implements anti-forensic measures such as memory scrubbing and self-deletion. Unlike typical ransomware, it leaves no ransom note on disk, conducting all extortion communications out-of-band through leak sites and direct contact. The threat actor gains initial access through compromised RDP credentials, uses legitimate RMM tools like RemotePC for persistence, and creates backdoor admin accounts. Victims span multiple countries and sectors, with notable incidents including Standard Bank Group in South Africa and Transitions Pro Centre Val de Loire in France.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/31/2026, 12:46:19 UTC

Technical Analysis

Prinz Eugen ransomware is a Go-based encryptor attributed to the ROOTBOY actor, observed since April 2026. It uses ChaCha20-Poly1305 encryption and prioritizes encrypting recently modified files. The malware incorporates anti-forensic measures like memory scrubbing and self-deletion to hinder analysis. Unlike typical ransomware, it does not drop ransom notes on disk but conducts extortion communications via leak sites and direct contact. Initial access is achieved through compromised RDP credentials, with persistence maintained using legitimate RemotePC RMM tools and backdoor admin accounts. The ransomware has targeted multiple sectors and countries, including high-profile victims such as Standard Bank Group and Transitions Pro Centre Val de Loire. There are no known exploits or patches since this is a malware threat rather than a software vulnerability.

Potential Impact

The ransomware encrypts victim files using strong ChaCha20-Poly1305 encryption, focusing on recently modified files to maximize operational disruption and pressure for ransom payment. Anti-forensic techniques complicate incident response and forensic analysis. The lack of ransom notes on disk and use of out-of-band communication channels may delay detection and complicate response efforts. The use of compromised RDP credentials and legitimate RMM tools for persistence increases the difficulty of preventing initial access and detecting malicious activity. The impact includes operational disruption, potential data loss, and financial extortion across multiple sectors and countries.

Defensive Guidance

As this is a malware threat rather than a software vulnerability, no patches or official fixes exist. Organizations should focus on securing RDP access by enforcing strong authentication controls, monitoring for unauthorized RDP logins, and limiting RDP exposure. Monitoring and controlling the use of legitimate RMM tools like RemotePC is recommended to detect misuse. Implementing robust account management to prevent unauthorized creation of admin accounts is advised. Incident response should include detection of indicators of compromise related to Prinz Eugen and rapid containment to prevent encryption spread. Regular backups and tested recovery procedures remain critical defenses against ransomware impact.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.threatdown.com/blog/prinz-eugen-ransomware-a-deep-dive-into-a-new-go-based-encryptor/"]
Adversary
ROOTBOY
Pulse Id
6a3d416ff54ce39010db1033
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domain6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onion
domainstndrdbnk.cc
domainprinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion
domaincaptchafestung.sbs
domaindarkempire.fun
domaing-captchafestung.sbs
domainold-pidop.ru
domainfestung-e.duckdns.org

Ip

ValueDescriptionCopy
ip212.80.7.74

Hash

ValueDescriptionCopy
hash686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4
hash17dd3f59f13f54a34761cef0c2b73cd7
hash9d94e2a15b75e1ef4487429ac71fc13e186c4a2d

Bitcoinaddress

ValueDescriptionCopy
bitcoinaddressbc1q2ztpcvqdaptej6uu2ywt9mrlatx6envu34rf0v

Url

ValueDescriptionCopy
urlhttps://212.80.7.74/serverscan.ps1
urlhttps://212.80.7.74/stager/mini
urlhttps://212.80.7.74/stager/ps1

Email

ValueDescriptionCopy

Threat ID: 6a3d46404853345fc11c397b

Added to database: 06/25/2026, 15:16:16 UTC

Last enriched: 07/31/2026, 12:46:19 UTC

Last updated: 08/10/2026, 04:02:37 UTC

Views: 312

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses