Proofpoint researchers identified a campaign impersonating the British postal carrier Royal Mail delivering Prince ransomware. Prince is a ransomware variant freely available on GitHub with a “disclaimer” that it is only designed for educational purposes.
Prince Ransomware
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Prince Ransomware in ATT&CK
19 distinct techniquesTechniques
19 techniques T1486 Data Encrypted for Impact T1566 Phishing T1547.009 Shortcut Modification T1105 Ingress Tool Transfer T1059.007 JavaScript T1566.001 Spearphishing Attachment T1560 Archive Collected Data T1685 Disable or Modify Tools T1053.005 Scheduled Task T1059.003 Windows Command Shell T1620 Reflective Code Loading T1140 Deobfuscate/Decode Files or Information T1036 Masquerading T1204.002 Malicious File T1112 Modify Registry T1548.002 Bypass User Account Control T1027 Obfuscated Files or Information T1491 Defacement T1059.001 PowerShell