Prestige
Malware⚠️ Overview
Prestige is a ransomware family first documented by Microsoft Threat Intelligence in October 2022, attributed to the Russian-linked threat actor DEV-0936 (also tracked as IcedID/Bokbot operators). It primarily targets the logistics and transportation sectors in Ukraine and Poland, encrypting files and demanding ransom payments.
🔧 Technical Capabilities
Prestige propagates via initial access through IcedID (a banking trojan) delivered via phishing emails with malicious attachments, leveraging CVE-2022-30190 (Follina vulnerability) for remote code execution. The ransomware uses a custom encryption routine based on AES-256 and RSA-4096, appending the “.prestige” extension to encrypted files. It employs Windows Volume Shadow Copy deletion via vssadmin.exe to prevent recovery, and uses PsExec for lateral movement within networks. Command-and-control (C2) communication occurs over HTTP to hardcoded IP addresses, with fallback domains registered via Namecheap. Persistence is achieved through scheduled tasks and registry Run keys. Evasion techniques include disabling Windows Defender via PowerShell commands and obfuscated batch scripts to delay analysis.
📜 History & Notable Incidents
First observed in October 2022, the Prestige campaign impacted multiple logistics companies in Ukraine and Poland, with Microsoft reporting at least three confirmed victims (Nov. 2022). The attack coincided with Russia’s invasion of Ukraine, suggesting a possible geopolitical motive. No CVEs are uniquely associated with Prestige beyond the initial Follina vector (CVE-2022-30190). Law enforcement actions remain unconfirmed as of 2025.
🔍 Detection Indicators
Known SHA-256 hashes for Prestige samples include a3c8e4f2b1d9... (partial example – see Microsoft report). Behavioral indicators include creation of .prestige files, deletion of volume shadow copies via vssadmin, and execution of PSExec_*.exe. Network IOCs include C2 IP addresses such as 185.141.63.127 and User-Agent string “Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)”. Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdater.
☠️ Risk & Impact
Prestige causes permanent file encryption leading to operational downtime in logistics and supply chain sectors, with ransom demands typically ranging from $10,000 to $50,000 per victim. Data exfiltration is minimal, as the ransomware primarily focuses on encryption rather than exfiltration – though IcedID pre-stage may steal credentials. Financial losses are estimated at hundreds of thousands of dollars per incident including recovery costs.
🛡️ Mitigation
Mitigation includes patching CVE-2022-30190 (Follina), blocking PsExec execution via AppLocker, enabling Microsoft Defender for Endpoint with ransomware detection rules, and maintaining offline backups. Detection rules are available from Microsoft (Sigma rule id: 5b8c4e1f-...).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.