Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

New Prinz Eugen ransomware targets recent files, avoids ransom notes

The Prinz Eugen ransomware is a hands-on-keyboard operation that gains initial access via compromised RDP credentials and manually deploys a Go-based payload ("servertool.exe") using legitimate RMM tools. It encrypts recently modified files with ChaCha20-Poly1305 to maximize impact and deliberately avoids dropping ransom notes to complicate detection. The malware overwrites its encryption key and self-deletes to prevent recovery.
Read Full Article →

Ransomware New Prinz Eugen ransomware targets recent files, avoids ransom notes June 22, 2026 Share By SC Staff A new ransomware operation dubbed "Prinz Eugen" has emerged, characterized by its strategy of prioritizing recently modified files for encryption and its omission of traditional ransom notes on affected systems, as reported by Bleeping Computer. The Prinz Eugen threat actor employs a hands-on-keyboard approach, leveraging legitimate remote monitoring and management (RMM) software and living-off-the-land tools, according to Threatdown. Initial access is believed to be gained through compromised RDP credentials, followed by the manual execution of a payload named "servertool.exe." Unlike many ransomware operations, Prinz Eugen does not operate under a ransomware-as-a-service model and is not currently recruiting affiliates. The malware, written in Go, encrypts files using ChaCha20-Poly1305, focusing on recently modified files to maximize impact. It avoids dropping ransom notes, a tactic intended to reduce forensic artifacts and complicate automated detection of the extortion phase. Researchers have identified at least five victims, with one instance involving a ransom demand of 1 Bitcoin that was refused. The operation's encryption strategy includes overwriting the encryption key with zeroes and self-deleting to prevent recovery. Source: Bleeping Computer An In-Depth Guide to Ransomware Get essential knowledge and practical strategies to protect your organization from ransomware attacks. Learn More SC Staff Related Phishing Malware campaign uses VirusTotal manipulation, legitimate news sites to gain reputation Laura French June 18, 2026 The clipboard hijacker campaign also uses “ghost networks” on social media to boost engagement. Phishing FBI warns of sophisticated Kali365 phishing service targeting Microsoft accounts SC Staff June 17, 2026 Coverage from Tech Radar indicates that a sophisticated phishing-as-a-service platform, known as Kali365, Octopi365, and Freedom365, is actively targeting Microsoft accounts. Ransomware Attackers drop DragonForce ransomware leveraging MS Teams relay systems Steve Zurier June 17, 2026 DragonForce ransomware abused Microsoft Teams relay infrastructure to hide C2 traffic. Related Events Cybercast Ransomware reloaded: Finding resilience when attackers wield AI On-Demand Event Virtual Conference Ransomware Resilience: Strategies to Defend, Mitigate, and Recover On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article