Prometheus
- First seen
- 2021-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:44:30
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
Ransomware written in .NET, apparently derived from the codebase of win.hakbit (Thanos) ransomware.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Thanos (yara-rule)
Reports & references
- Palo Alto Unit 42 — Prometheus Ransomware (report)
- medium.com — The Road To Ransomware Resilience C1Ca37036Efd (report)
- therecord.media — Decryptor Released For Prometheus Ransomware Victims (report)
- Palo Alto Unit 42 — Prometheus Ransomwar (report)
- id-ransomware.blogspot.com — Prometheus Ransomware (report)
- medium.com — Prometheus Decryptor 6933E7Bac1Ea (report)
- medium.com — Prometheus X Spook Prometheus Ransomware Rebranded Spook Ransomware 6F93Bd8Ab5Dd (report)
- securityintelligence.com — Ransomware Encryption Goes Wrong (report)
- twitter.com — 1441252744258461699 (report)
- cybereason.com — Cybereason Vs. Prometheus Ransomware (report)
- sentinelone.com — Spook Ransomware Prometheus Derivative Names Those That Pay Shames Those That Dont (report)
- ransomlook.io — Prometheus (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Prometheus (report)