Back to Resources

SentinelOne VS Prestige Ransomware – Protection, Detection and Response

Prestige ransomware was first observed in October 2022. The malware has been tied to multiple targeted attacks affecting entities in Poland and Ukraine. Prestige-centric campaigns have not yet been linked to any other prior, specific, attacks against Ukraine. Initial footholds are often obtained via COTS or LOLBINS (Impacket WMIexec, Remote Exec, ntdsutil.exe, winPEAS) Once launched, the malware will locate files matching the prescribed criteria for encryption. Affected files are noted with a “.enc” extension. The malware also registered a custom file handler (via registry). In addition, the malware will attempt to delete Volume Shadow Copies and the local Backup Catalog (wbadmin.exe).

SentinelOne Singularity™ blocks and prevents Prestige ransomware attacks.

#malware #ransomware #Prestige #ukraine

지금 읽기

세계에서 가장 앞선 사이버 보안 플랫폼 경험하기

지능적인 자율형 사이버 보안 플랫폼이 현재와 미래의 조직을 어떻게 보호할 수 있는지 알아보세요.