Prinz Eugen: The Ransomware That Skips the Ransom Note
A new ransomware operation called Prinz Eugen is hitting victims without ever explaining why. According to researchers at ThreatDown (Malwarebytes' enterprise security arm), the group leaves no ransom note at all — victims discover the attack only after their most recently modified files are already encrypted.
The group works hands-on-keyboard rather than relying on automated tools. Initial access starts with stolen RDP (Remote Desktop Protocol — remote login access to a computer) credentials. Once inside, an operator manually downloads and runs the main payload, a file named servertool.exe, rather than letting malware spread on its own. In one investigated case, the attackers installed RemotePC, a legitimate remote-access tool, and created a hidden backdoor administrator account to maintain access even if the original entry point closed.
Unlike most modern ransomware crews, Prinz Eugen does not run as a ransomware-as-a-service (RaaS — a model where developers rent their ransomware out to other criminals) operation. There is no affiliate program, no recruitment drive, just a small group working directly.
The file-prioritisation detail matters: encrypting your newest files first means the most current, most valuable work is gone before older backups even register as a target.
What to do: Disable RDP entirely if you do not need remote access, or lock it behind multi-factor authentication if you do. Treat any RemotePC installation you did not set up yourself as a compromise indicator, and audit your administrator account list for anything unfamiliar.
Sources

