CSIDB logo
Threat actor

Prometheus

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
2 incidents
First seen
2016-10-02
Last seen
2021-06-02
Updated
2026-08-01 19:38
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Prometheus is a ransomware group known by that alias and is believed to operate from Russia. The group has publicly affiliated itself with the REvil ransomware operation, indicating a collaborative relationship with a established criminal syndicate. Prometheus emerged in mid‑2021 after a period of inactivity, announcing its return through a darkweb blog that detailed its activities and offered analysis of its malware. The group’s primary tool is the Thanos ransomware, a 32‑bit .NET executable that employs code obfuscation and base64 encoding to evade detection. Thanos is designed to terminate specific processes such as excel.exe and steam.exe, stop and start Windows services, modify firewall rules, and encrypt files using AES encryption. After encryption, the malware deposits ransom notes in both HTA and plain text formats, demanding payment for decryption keys. These notes confirm the group’s intent to extort victims rather than pursue espionage or pure disruption.

The only publicly reported targeting attributed to Prometheus involves a manufacturing organization attacked on June 2 2021, where the Thanos ransomware was deployed. This incident shows the group’s focus on industrial sectors, although no further sectoral or geographic targeting details are available from the sources. The attack followed a pattern of service disruption prior to encryption, aiming to maximize operational impact and pressure victims into compliance. The use of .NET based ransomware with built‑in process killing and firewall manipulation reflects a tooling style that emphasizes hindering recovery efforts while maintaining a relatively lightweight payload.

Prometheus’s affiliation with REvil provides a clear criminal consortium link, though no state sponsorship or direct government ties are documented in the open sources. The group’s observable tactics include leveraging obfuscated .NET binaries, employing base64 encoded strings for configuration, and creating ransom notes in multiple formats to increase the likelihood of victim interaction. While the exact initial access vectors remain unspecified in the provided material, the described post‑infection behaviors illustrate a coordinated approach to disrupt services, hinder forensic analysis, and enforce payment demands. This synthesis of facts constitutes the extent of verifiable information about the Prometheus threat actor based on the supplied context.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB