Prometheus Different Thanos-based Ransomware Prometheus Ransomware "GotAllDone" Ransomware Prometheus NextGen Ransomware Variants, variation, modification: Getin, CGP, Haron (Chaddad), Boooom, Spook, ltnuhr, Steriok, Unlock, ZZZZZZZZZZ, Matilan.
Prometheus
Prometheus is a Windows ransomware family first observed in February 2021 and widely assessed as a Thanos-derived variant built from leaked Thanos code.
Profile source: Mallory opens in a new tabPrometheus
Family profile
Prometheus is a Windows ransomware family first observed in February 2021 and widely assessed as a Thanos-derived variant built from leaked Thanos code. It is associated with a double-extortion operation that encrypts victim files while also threatening to leak stolen data through a dedicated extortion site and negotiation portal. The operators publicly claimed links to REvil, but reporting consistently found no technical evidence supporting that affiliation. Victims spanned multiple sectors, with manufacturing and transportation/logistics appearing prominently among observed cases, alongside government, financial, healthcare, energy, legal, consulting, agriculture, and other enterprises across several regions.
Prometheus is implemented as a .NET ransomware strain targeting Windows environments. Across analyses, it has been reported using Salsa20 for file encryption, with some reporting on Prometheus-linked Thanos samples describing AES-based encryption behavior in related campaigns. Prometheus appends victim-specific extensions to encrypted files, drops text and HTA ransom notes, and uses common Thanos-family markers also seen in related variants such as Haron, Spook, and Midas. The malware attempts to maximize encryption success by terminating processes and services associated with backups, databases, office applications, and security tooling, including artifacts related to the Raccine anti-ransomware utility. It has also been observed modifying service configurations and, in some reporting on Prometheus-linked samples, altering firewall or registry settings as part of pre-encryption preparation and defense evasion.
The family is notable for weaknesses identified in some Prometheus encryption implementations. Multiple researchers documented flawed key generation tied to system tick count or uptime, enabling development of decryptors that could recover at least some encrypted files, especially where known file headers or other recoverable parameters were available. These weaknesses distinguished Prometheus from more mature ransomware families whose cryptography generally prevents recovery without attacker-held keys.
Prometheus forms part of a broader cluster of Thanos-based ransomware activity and has been linked genealogically and operationally to later variants including Haron and Spook. Its emergence illustrates how leaked ransomware builders enabled rapid rebranding, customization, and commercialization of extortion operations by multiple actors.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
- Persistence
Operational record
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
Prometheus in ATT&CK
18 distinct techniquesTechniques
18 techniquesReporting
Research mentioning Prometheus
Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RedRum, Tycoon
Tycoon, also tracked as RedRum, Grinch, and in some reporting alongside Thanos-linked variants, emerged as a manually deployed ransomware threat against enterprise environments on both Windows and Linux. Operators were reported to gain access through vulnerable or exposed RDP services, then encrypt files with AES-256-GCM while protecting encryption keys with RSA-1024. The malware appended extensions including .redrum, .grinch, .thanos, .eruption, and .magneto, and dropped a ransom note named decryption.txt using contact addresses such as moncler@tutamail.com and moncler@cock.li. Reporting also tied the activity to broader Thanos ransomware development, a .NET-based RaaS ecosystem that enabled extensive customization, persistence, anti-analysis, and defense-evasion features across multiple later variants. The malware was described as deleting shadow copies and disabling recovery and firewall protections while avoiding some system files and directories to keep infected systems operational. Historical tracking indicates some early Hakbit-identified and RedRum samples could be decrypted, including with an Emsisoft decryptor, while later corrected Thanos-derived variants adopted stronger RSA-based encryption that generally prevented recovery without the attackers' private key.