Skip to content

Prometheus

Prometheus is a Windows ransomware family first observed in February 2021 and widely assessed as a Thanos-derived variant built from leaked Thanos code.

Profile source: Mallory opens in a new tab

Prometheus

Family profile

Prometheus is a Windows ransomware family first observed in February 2021 and widely assessed as a Thanos-derived variant built from leaked Thanos code. It is associated with a double-extortion operation that encrypts victim files while also threatening to leak stolen data through a dedicated extortion site and negotiation portal. The operators publicly claimed links to REvil, but reporting consistently found no technical evidence supporting that affiliation. Victims spanned multiple sectors, with manufacturing and transportation/logistics appearing prominently among observed cases, alongside government, financial, healthcare, energy, legal, consulting, agriculture, and other enterprises across several regions.

Prometheus is implemented as a .NET ransomware strain targeting Windows environments. Across analyses, it has been reported using Salsa20 for file encryption, with some reporting on Prometheus-linked Thanos samples describing AES-based encryption behavior in related campaigns. Prometheus appends victim-specific extensions to encrypted files, drops text and HTA ransom notes, and uses common Thanos-family markers also seen in related variants such as Haron, Spook, and Midas. The malware attempts to maximize encryption success by terminating processes and services associated with backups, databases, office applications, and security tooling, including artifacts related to the Raccine anti-ransomware utility. It has also been observed modifying service configurations and, in some reporting on Prometheus-linked samples, altering firewall or registry settings as part of pre-encryption preparation and defense evasion.

The family is notable for weaknesses identified in some Prometheus encryption implementations. Multiple researchers documented flawed key generation tied to system tick count or uptime, enabling development of decryptors that could recover at least some encrypted files, especially where known file headers or other recoverable parameters were available. These weaknesses distinguished Prometheus from more mature ransomware families whose cryptography generally prevents recovery without attacker-held keys.

Prometheus forms part of a broader cluster of Thanos-based ransomware activity and has been linked genealogically and operationally to later variants including Haron and Spook. Its emergence illustrates how leaked ransomware builders enabled rapid rebranding, customization, and commercialization of extortion operations by multiple actors.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Persistence

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Prometheus

Prometheus Different Thanos-based Ransomware Prometheus Ransomware "GotAllDone" Ransomware Prometheus NextGen Ransomware Variants, variation, modification: Getin, CGP, Haron (Chaddad), Boooom, Spook, ltnuhr, Steriok, Unlock, ZZZZZZZZZZ, Matilan.

MITRE ATT&CK

Prometheus in ATT&CK

18 distinct techniques

Reporting

Research mentioning Prometheus

Dec 5
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": RedRum, Tycoon

Tycoon, also tracked as RedRum, Grinch, and in some reporting alongside Thanos-linked variants, emerged as a manually deployed ransomware threat against enterprise environments on both Windows and Linux. Operators were reported to gain access through vulnerable or exposed RDP services, then encrypt files with AES-256-GCM while protecting encryption keys with RSA-1024. The malware appended extensions including .redrum, .grinch, .thanos, .eruption, and .magneto, and dropped a ransom note named decryption.txt using contact addresses such as moncler@tutamail.com and moncler@cock.li. Reporting also tied the activity to broader Thanos ransomware development, a .NET-based RaaS ecosystem that enabled extensive customization, persistence, anti-analysis, and defense-evasion features across multiple later variants. The malware was described as deleting shadow copies and disabling recovery and firewall protections while avoiding some system files and directories to keep infected systems operational. Historical tracking indicates some early Hakbit-identified and RedRum samples could be decrypted, including with an Emsisoft decryptor, while later corrected Thanos-derived variants adopted stronger RSA-based encryption that generally prevented recovery without the attackers' private key.

Oct 1
Id Ransomware

Шифровальщики-вымогатели The Digest "Crypto-Ransomware": Hakbit, Thanos

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.