Prinz Eugen ransomware: a deep dive into a new Go-based encryptor
Prinz Eugen is a newly discovered Go-based ransomware family first observed in April 2026, attributed to an actor known as ROOTBOY. The encryptor employs sophisticated techniques including ChaCha20-Poly1305 encryption, prioritizes recently modified files to maximize pressure on victims, and implements anti-forensic measures such as memory scrubbing and self-deletion. Unlike typical ransomware, it leaves no ransom note on disk, conducting all extortion communications out-of-band through leak sites and direct contact. The threat actor gains initial access through compromised RDP credentials, uses legitimate RMM tools like RemotePC for persistence, and creates backdoor admin accounts. Victims span multiple countries and sectors, with notable incidents including Standard Bank Group in South Africa and Transitions Pro Centre Val de Loire in France.
AI Analysis
Technical Summary
Prinz Eugen ransomware is a Go-based encryptor attributed to the ROOTBOY actor, observed since April 2026. It uses ChaCha20-Poly1305 encryption and prioritizes encrypting recently modified files. The malware incorporates anti-forensic measures like memory scrubbing and self-deletion to hinder analysis. Unlike typical ransomware, it does not drop ransom notes on disk but conducts extortion communications via leak sites and direct contact. Initial access is achieved through compromised RDP credentials, with persistence maintained using legitimate RemotePC RMM tools and backdoor admin accounts. The ransomware has targeted multiple sectors and countries, including high-profile victims such as Standard Bank Group and Transitions Pro Centre Val de Loire. There are no known exploits or patches since this is a malware threat rather than a software vulnerability.
Potential Impact
The ransomware encrypts victim files using strong ChaCha20-Poly1305 encryption, focusing on recently modified files to maximize operational disruption and pressure for ransom payment. Anti-forensic techniques complicate incident response and forensic analysis. The lack of ransom notes on disk and use of out-of-band communication channels may delay detection and complicate response efforts. The use of compromised RDP credentials and legitimate RMM tools for persistence increases the difficulty of preventing initial access and detecting malicious activity. The impact includes operational disruption, potential data loss, and financial extortion across multiple sectors and countries.
Mitigation Recommendations
As this is a malware threat rather than a software vulnerability, no patches or official fixes exist. Organizations should focus on securing RDP access by enforcing strong authentication controls, monitoring for unauthorized RDP logins, and limiting RDP exposure. Monitoring and controlling the use of legitimate RMM tools like RemotePC is recommended to detect misuse. Implementing robust account management to prevent unauthorized creation of admin accounts is advised. Incident response should include detection of indicators of compromise related to Prinz Eugen and rapid containment to prevent encryption spread. Regular backups and tested recovery procedures remain critical defenses against ransomware impact.
Indicators of Compromise
- domain: 6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onion
- domain: stndrdbnk.cc
- ip: 212.80.7.74
- domain: prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion
- hash: 686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4
- bitcoinaddress: bc1q2ztpcvqdaptej6uu2ywt9mrlatx6envu34rf0v
- url: https://212.80.7.74/serverscan.ps1
- url: https://212.80.7.74/stager/mini
- url: https://212.80.7.74/stager/ps1
- domain: captchafestung.sbs
- domain: darkempire.fun
- domain: g-captchafestung.sbs
- domain: old-pidop.ru
- email: [email protected]
- email: [email protected]
- domain: festung-e.duckdns.org
- hash: 17dd3f59f13f54a34761cef0c2b73cd7
- hash: 9d94e2a15b75e1ef4487429ac71fc13e186c4a2d
Prinz Eugen ransomware: a deep dive into a new Go-based encryptor
Description
Prinz Eugen is a newly discovered Go-based ransomware family first observed in April 2026, attributed to an actor known as ROOTBOY. The encryptor employs sophisticated techniques including ChaCha20-Poly1305 encryption, prioritizes recently modified files to maximize pressure on victims, and implements anti-forensic measures such as memory scrubbing and self-deletion. Unlike typical ransomware, it leaves no ransom note on disk, conducting all extortion communications out-of-band through leak sites and direct contact. The threat actor gains initial access through compromised RDP credentials, uses legitimate RMM tools like RemotePC for persistence, and creates backdoor admin accounts. Victims span multiple countries and sectors, with notable incidents including Standard Bank Group in South Africa and Transitions Pro Centre Val de Loire in France.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Prinz Eugen ransomware is a Go-based encryptor attributed to the ROOTBOY actor, observed since April 2026. It uses ChaCha20-Poly1305 encryption and prioritizes encrypting recently modified files. The malware incorporates anti-forensic measures like memory scrubbing and self-deletion to hinder analysis. Unlike typical ransomware, it does not drop ransom notes on disk but conducts extortion communications via leak sites and direct contact. Initial access is achieved through compromised RDP credentials, with persistence maintained using legitimate RemotePC RMM tools and backdoor admin accounts. The ransomware has targeted multiple sectors and countries, including high-profile victims such as Standard Bank Group and Transitions Pro Centre Val de Loire. There are no known exploits or patches since this is a malware threat rather than a software vulnerability.
Potential Impact
The ransomware encrypts victim files using strong ChaCha20-Poly1305 encryption, focusing on recently modified files to maximize operational disruption and pressure for ransom payment. Anti-forensic techniques complicate incident response and forensic analysis. The lack of ransom notes on disk and use of out-of-band communication channels may delay detection and complicate response efforts. The use of compromised RDP credentials and legitimate RMM tools for persistence increases the difficulty of preventing initial access and detecting malicious activity. The impact includes operational disruption, potential data loss, and financial extortion across multiple sectors and countries.
Defensive Guidance
As this is a malware threat rather than a software vulnerability, no patches or official fixes exist. Organizations should focus on securing RDP access by enforcing strong authentication controls, monitoring for unauthorized RDP logins, and limiting RDP exposure. Monitoring and controlling the use of legitimate RMM tools like RemotePC is recommended to detect misuse. Implementing robust account management to prevent unauthorized creation of admin accounts is advised. Incident response should include detection of indicators of compromise related to Prinz Eugen and rapid containment to prevent encryption spread. Regular backups and tested recovery procedures remain critical defenses against ransomware impact.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.threatdown.com/blog/prinz-eugen-ransomware-a-deep-dive-into-a-new-go-based-encryptor/"]
- Adversary
- ROOTBOY
- Pulse Id
- 6a3d416ff54ce39010db1033
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domain6cudc5cqa2bjpwdhcwm2lj6dbqejjjqzeo6ipwvmbazr6cgu7vfk3dad.onion | — | |
domainstndrdbnk.cc | — | |
domainprinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion | — | |
domaincaptchafestung.sbs | — | |
domaindarkempire.fun | — | |
domaing-captchafestung.sbs | — | |
domainold-pidop.ru | — | |
domainfestung-e.duckdns.org | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip212.80.7.74 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4 | — | |
hash17dd3f59f13f54a34761cef0c2b73cd7 | — | |
hash9d94e2a15b75e1ef4487429ac71fc13e186c4a2d | — |
Bitcoinaddress
| Value | Description | Copy |
|---|---|---|
bitcoinaddressbc1q2ztpcvqdaptej6uu2ywt9mrlatx6envu34rf0v | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://212.80.7.74/serverscan.ps1 | — | |
urlhttps://212.80.7.74/stager/mini | — | |
urlhttps://212.80.7.74/stager/ps1 | — |
| Value | Description | Copy |
|---|---|---|
email[email protected] | — | |
email[email protected] | — |
Threat ID: 6a3d46404853345fc11c397b
Added to database: 06/25/2026, 15:16:16 UTC
Last enriched: 07/31/2026, 12:46:19 UTC
Last updated: 08/10/2026, 04:02:37 UTC
Views: 312
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.