EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 21, 20263 min read

Security Briefing | June 21, 2026 - New Prinz Eugen Ransomware Skips Ransom Notes, Mastra Supply Chain Attack Linked to North Korea

A new ransomware variant called Prinz Eugen is encrypting recently modified files first and leaving no ransom note, complicating detection. Separately, Microsoft has attributed the Mastra AI npm supply chain attack, which compromised over 140 packages, to North Korean state-sponsored group Sapphire Sleet (BlueNoroff).

By EACA Summit Content Team

Security Briefing | June 21, 2026 - New Prinz Eugen Ransomware Skips Ransom Notes, Mastra Supply Chain Attack Linked to North Korea

1. New Prinz Eugen Ransomware Prioritizes Recent Files for Encryption

A new ransomware operation named 'Prinz Eugen' has been observed encrypting recently modified files first and leaving no ransom note on compromised systems. This behavior suggests a focus on maximizing disruption by targeting active projects and critical data.

Verified Facts

  • Prinz Eugen ransomware prioritizes recently modified files for encryption
  • The ransomware does not drop a ransom note on the system
  • The operation was first reported by BleepingComputer on June 20, 2026

Evidence

  • BleepingComputer article dated June 20, 2026

Impact

Defenders should monitor for unusual file encryption patterns, especially on recent files, and ensure backups are isolated. The lack of a ransom note may delay detection and response.

Confidence Level: High

BleepingComputer

2. Mastra AI Supply Chain Attack Update: Microsoft Attributes Campaign to North Korean Hackers

A hooded hacker silhouette before a world map highlighting North Korea with attack vectors and a high-confidence state-sponsored attribution assessment.

Microsoft has attributed the Mastra AI supply chain attack, which compromised over 140 npm packages, to the North Korean hacking group Sapphire Sleet (also known as BlueNoroff). The attack targeted developers and users of the Mastra AI framework.

Verified Facts

  • The attack compromised more than 140 npm packages
  • Microsoft attributes the attack to North Korean group Sapphire Sleet (BlueNoroff)
  • The attack targeted the Mastra AI supply chain

Evidence

  • Microsoft attribution statement
  • BleepingComputer article dated June 20, 2026

Impact

Organizations using Mastra AI or affected npm packages should audit their dependencies and check for signs of compromise. This highlights the ongoing risk of supply chain attacks targeting AI frameworks, and confirms state-sponsored involvement in a previously unattributed incident.

Confidence Level: High

BleepingComputer

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings