216.73.217.22

Security Brief: Royal Mail Lures Deliver Open Source Prince Ransomware

· Published 02/10/2024 16:09 · Modified 02/10/2024 16:21

Export JSON

Essential information

Published
02/10/2024 16:09
Modified
02/10/2024 16:21
Tags
2024-10-02 contact forms destructive attack github obfuscation open-source malware phishing prince prince ransomware royal mail
Related entities
3 observables, 10 techniques (mitre), 1 malware, 2 others

Description

A campaign impersonating was identified delivering , an open-source variant available on . The low-volume attack targeted UK and US organizations in mid-September, often originating from on target websites. The ransomware lacks decryption mechanisms and data exfiltration capabilities, making it purely destructive. The attack chain involves multiple stages, including PDF lures, ZIP files, shortcuts, and obfuscated scripts, ultimately leading to the execution of the . The campaign's attribution remains unclear, but the ransomware's creator offers customization services. This activity highlights the ongoing threat of freely available malware and the importance of user awareness in identifying suspicious emails and attachments.

External references