The real damage starts before encryption. Prinz Eugen works like a hands-on operator inside the network, using stolen RDP and legitimate RemotePC sessions to move around, then launching encryption itself instead of blasting out a noisy automated payload. That lets the crew act like a trusted admin and hit the newest work first, before defenders even see a classic ransomware pattern.
Threatdown says the group used a backdoor administrator account for persistence and focused on recently modified files, with ties to RemotePC and stolen RDP credentials in the observed incident. The encryptor leaves no ransom note and skips the usual RaaS affiliate model, which makes the intrusion look less like commodity ransomware and more like manual operator access with encryption layered on top.
For teams that rely on remote access for server administration, the threat is the access window itself. If attackers can keep a legitimate-looking session alive, patching the payload does not undo the control they already gained or the files they already chose.