Prinz Eugen hands-on-keyboard ransomware activity
Malware Activity
Updated: 20.06.2026 18:23
· First: 20.06.2026 18:23
· 📰 1 src / 1 articles
· H score: 4
The Prinz Eugen ransomware operation is actively using hands-on-keyboard tradecraft and legitimate RMM tools, which makes intrusions harder to spot and contain. Researchers say the operators likely start with stolen RDP credentials, then manually deploy servertool.exe and maintain access with RemotePC. The encryptor focuses on recently modified files, skips a ransom note, and pushes victims toward out-of-band extortion. The activity has already been tied to multiple victims, including a Standard Bank breach demand of 1 BTC.