Prince now has a Windows Defender flag, namely “Ransom:Win64/PrinceRansom.YAA!MTB”. This means that Prince Ransomware will no longer bypass Windows Defender without modifications to remove the signature.
If, for whatever reason, bypassing Windows Defender is a priority for you, contact me on Telegram and I will accept payment for any changes you may require.
Prince is a ransomware written from scratch in Go. It uses a mixture of ChaCha20 and ECIES cryptography in order to encrypt files securely so that they cannot be recovered by traditional recovery tools.
Files which have been encrypted by Prince can only be decrypted using the corresponding decryptor.
Build.bat
file.Builder.exe
file in the current directory.Builder.exe
program.Encryptor
and Decryptor
directories, as it will not be able to build them otherwise.Prince-Built.exe
file is the encryptor. Use caution when handling it as it can cause a lot of damage to your system.Decryptor-Built.exe
file is the decryptor. It will only decrypt files which were decrypted by the corresponding encryptor.I chose this unique combination of encryption methods for several reasons:
For more information click here.
Helix is a modern, terminal-based text editor designed for developers seeking speed, efficiency, and advanced…
Azure-SecOps is a critical framework that integrates security tools and operational processes to ensure robust…
Tauri is an innovative framework designed to create lightweight, high-performance desktop applications. It empowers developers…
Linkook is a powerful Open Source Intelligence (OSINT) tool designed to uncover interconnected social media…
Lapce is a modern, open-source code editor designed for speed, efficiency, and extensibility. Built entirely…
The recent leak of Black Basta’s internal communications, spanning over 200,000 chat messages, has provided…