Prestige ransomware
Prestige ransomware (canonical Microsoft Threat Intelligence Center MSTIC naming per October 14, 2022 disclosure based on self-naming "Prestige ranusomeware" typo in ransom note.
Microsoft initial tracking as DEV-0960 - IRIDIUM element-themed November 10, 2022 attribution - Seashell Blizzard weather-themed April 2023 rename = Sandworm) is a destructive operation disguised as ransomware deployed October 11, 2022 by Sandworm against transportation + logistics sectors in Ukraine + Poland, the first Sandworm destructive attack against Poland during the war + canonical illustration of Sandworm tactical shift toward organizations directly supplying or transporting humanitarian + military assistance to Ukraine.
Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre-weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator) via Microsoft MSTIC canonical November 10, 2022 IRIDIUM attribution update ("MSTIC assesses that IRIDIUM very likely executed the Prestige ransomware-style attack... publicly overlapping with Sandworm... consistently active in the war in Ukraine and has been linked to destructive attacks since the start of the war") + ESET parallel Sandworm attribution per APT Activity Report T3 2022; standalone malware platform cluster paralleling ransomboggs + swiftslicer in 2023+ Sandworm destructive cyberweapon evolution cell extending v0.1.130 Ukraine 2022 wartime wiper cell into late 2022.
operational attack architecture: long-term interactive compromise of multiple victims dating back to March 2022 - simultaneous within-hour mass deployment October 11, 2022 across all target organizations (~7-month dwell time per Microsoft); highly privileged domain credentials acquisition prerequisite enabling three observed deployment methods per Microsoft (Method 1: Prestige binary copied to AD domain controller + deployed via Group Policy.
Method 2: Prestige binary copied to AD domain controller + executed via encoded PowerShell command remote scheduled task.
Method 3: Prestige binary copied to AD domain controller + executed via WMI remote command)
CryptoPP C++ library AES encryption with cluster-defining .enc file extension marker.
sample compiled October 7, 2022 + written in C/C++ per Netskope (4-day compilation- to-deployment window)
cluster-defining destructive- operation-disguised-as-ransomware tradecraft echoing NotPetya 2017 pattern, per ESET APT Activity Report T3 2022: "In addition to data-wiping malware, ESET discovered Sandworm attacks using ransomware as a wiper. In those attacks, although ransomware was used, the final objective was the same as for the wipers: data destruction. Unlike traditional ransomware attacks, the Sandworm operators do not intend to provide a decryption key".
signature tactical shift to Polish targets during war (cluster-defining first Sandworm Polish attack, per Microsoft: "may highlight a measured shift in IRIDIUM's destructive attack calculus, signaling increased risk to organizations directly supplying or transporting humanitarian or military assistance to Ukraine")
victimology overlap with HermeticWiper February 2022 victims per Netskope + Microsoft (continuous Sandworm targeting through 2022 period); Microsoft April 2023 weather-taxonomy renaming IRIDIUM - Seashell Blizzard consolidated Sandworm attribution.
AttackIQ canonical August 2, 2024 "Emulating Sandworm's Prestige Ransomware" (Francis Guibernau) emulation methodology adoption + PolySwarm + Netskope + Anvilogic + multiple industry technical analyses.
ESET DynoWiper January 2026 retrospective catalogs Prestige in chronological Sandworm destructive malware family (HermeticWiper + HermeticRansom + CaddyWiper + DoubleZero + ARGUEPATCH + ORCSHRED + SOLOSHRED + AWFULSHRED + Prestige ransomware + RansomBoggs ransomware + SDelete-based wipers + BidSwipe + ROARBAT + SwiftSlicer + NikoWiper + SharpNikoWiper + ZEROLOT + Sting wiper + ZOV wiper); operationally significant short compilation-to- deployment timeline (October 7 - October 11) + simultaneous within-hour mass deployment + long-term pre-positioning combination demonstrates Sandworm mature operational tempo + tradecraft.
cluster fills late-2022 ransomware-as-wiper position in 2023+ Sandworm destructive cyberweapon evolution cell; canonical illustration of Sandworm late-2022 tactical shift to Polish humanitarian + military aid supply chain targets + ransomware-as-wiper tradecraft cited in essentially all subsequent Sandworm + Ukraine war + ransomware-as-wiper industry analyses through 2022-2026 period.