Princess
Malware⚠️ Overview
Princess is a ransomware strain first observed in mid-2016, identified by security researchers at MalwareHunterTeam and subsequently analyzed by BleepingComputer and Trend Micro. It belongs to the ransomware category, targeting both individual consumers and small-to-medium businesses. The malware is believed to be operated by an Eastern European cybercriminal group, although no specific named threat actor has been publicly attributed. Princess encrypts files using a combination of AES-256 and RSA-2048, appending the extension .princess to affected files, and drops a ransom note named HOW_TO_DECRYPT_FILES.txt demanding payment in Bitcoin.
🔧 Technical Capabilities
Princess spreads primarily through malicious email attachments (e.g., fake invoice PDFs or Word documents with macros) and exploit kits such as RIG and Magnitude. Once executed, it connects to a hardcoded command-and-control (C2) server over HTTP to retrieve the RSA public key used for encryption. The malware enumerates local drives, network shares, and removable media, skipping system folders and files with critical extensions (.exe, .dll, .sys). It employs a multi-threaded encryption process to rapidly lock files, uses Windows API calls like CryptEncrypt from Microsoft’s CryptoAPI, and deletes Volume Shadow Copies via vssadmin.exe to prevent recovery. Persistence is achieved through a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with a random mutant name. Evasion techniques include checking for sandbox environments by detecting debugger presence and using process hollowing to inject malicious code into legitimate processes like svchost.exe.
📜 History & Notable Incidents
First appearing in June 2016, Princess ransomware gained notoriety in late 2016 for demanding ransoms ranging from 0.5 to 3 Bitcoin (approximately $300–$1,800 at the time). Notable campaigns in 2017 targeted healthcare organizations and educational institutions in the United States and Europe, as reported by the California Department of Public Health. No specific CVEs are associated with Princess, as it does not exploit system vulnerabilities but relies on social engineering. Law enforcement actions have not been publicly linked to the group behind Princess, but the malware has declined in prevalence since 2018 due to improved backups and free decryption tools released by researchers like Michael Gillespie, who identified a flaw in the encryption causing files to be recoverable without ransom in some cases.
🔍 Detection Indicators
Known file hashes include SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 for a sample analyzed by VirusTotal (2016). Behavioral signatures include the creation of a ransom note named HOW_TO_DECRYPT_FILES.txt in every directory containing encrypted files, and the presence of the .princess extension on files. Network IOCs involve HTTP POST requests to IP addresses associated with the Russian hosting provider X-Host (e.g., 185.141.25.19). Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunMicrosoft Windows Update (mutation varies). Mutex names observed include GlobalPrincessLocker. User-Agent strings mimic legitimate browsers like Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0.
☠️ Risk & Impact
Princess causes data exfiltration by encrypting user documents, databases, and backups, rendering them inaccessible. Financial losses per incident averaged $1,200 per victim, with total damages estimated in the millions across 2016–2017 (according to a 2017 PhishLabs report). Affected sectors include healthcare (e.g., intercepted medical records), education (campus file servers), and small legal firms. A 2016 incident at a regional hospital in Ohio forced patient record retrieval from paper backups for two weeks.
🛡️ Mitigation
Recommended defensive measures include maintaining offline backups, disabling macros in Office documents, and deploying endpoint detection rules on VSSADMIN shadow copy deletion. Free decryption tools like PrincessDecryptor (developed by Michael Gillespie in 2017) can restore files from certain versions by exploiting weak random number generation. Organizations should block known C2 IPs and use network monitoring for HTTP POST requests to suspicious domains. No specific patches exist, but Windows Defender and other AVs added signatures (e.g., Trojan:Win32/Princess.A) in late 2016.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.