SentinelOne Vs. Prometheus Ransomware – Protect Mode
Prometheus ransomware emerged in mid-2021, joining the ranks of Avaddon, Grief, and other prolific ransomware families. Current intelligence indicates possible ties to both the REvil “Gang”, and actors behind the Thanos ransomware family/service. Prometheus hosts a TOR (darkweb)-based blog used for publicizing victims’ data. The Prometheus group is indiscriminate when it comes to targets. They have successfully targeted entities in the Government, Healthcare, Oil & Gas, and more.
Upon execution, Prometheus attempts to disable (taskkill) multiple services and processes which may interfere with the encryption process. This includes common security tools, backup utilities, and database applications. The malware will also attempt to delete shadow copies and take additional measures to inhibit the recovery process.
See how SentinelOne quarantines and kills Prometheus Ransomware.
#ransomware #prometheus #cybersecurity #infosec #REvil #darkweb