Netskope Threat Labs

Prestige

ATP Sandbox Adv. HeuristicsAV

Prestige is ransomware targeting critical infrastructure and logistics organizations in Ukraine and neighboring countries, first observed in late 2022. Its operators delivered the payload through compromised cloud service connections, an unusual vector that highlighted the role of cloud tooling in destructive intrusions. The campaign marked the first time researchers observed Western made ransomware deployed against Ukrainian infrastructure, a notable shift in the regional conflict's cyber dimension.

First seen
October 2022
Last seen
October 2026

9 techniques across 4 tactics.

TA0002 Execution

TA0007 Discovery

  • T1083File and Directory Discovery

TA0040 Impact

  • T1486Data Encrypted for Impact
  • T1489Service Stop
  • T1490Inhibit System Recovery

TA0112 Defense Impairment

  • T1112Modify Registry
  • T1484Domain or Tenant Policy Modification
Alert Name
Trojan.Ransom.Prestige.1
Win32.Ransomware.Prestige