Prometei is a modular, multi-stage botnet malware family targeting Windows and Linux systems, primarily to mine Monero using XMRig. Publicly documented in July 2020, it has historical artifacts dating to 2016 and has continued to evolve through additional modules, remote-control functionality, and self-updating mechanisms. Its financially motivated operations opportunistically compromise enterprise servers and other systems across industries, including finance, insurance, retail, manufacturing, utilities, travel, and construction.
Prometei gains access through vulnerable services and weak or stolen credentials. Documented campaigns exploited Microsoft Exchange vulnerabilities CVE-2021-26858 and CVE-2021-27065, deploying China Chopper web shells to execute commands and retrieve the malware. Its propagation components use SMB, RDP, SSH, Microsoft SQL Server, and PostgreSQL, combining credential reuse and brute-force attacks with EternalBlue and BlueKeep exploitation. An automated SQL-server intrusion chain also used CVE-2016-0099 for privilege escalation.
The malware harvests credentials using a customized Mimikatz component and modifies Windows credential-handling settings to retain credential material in memory. Its backdoor supports arbitrary command execution, payload downloads, file transfer, system-information collection, port checking, bot updates, and mining control. Expanded versions provide directory retrieval, clipboard access, simulated keyboard and mouse input, and additional access through a bundled PHP web shell. Harvested credentials and other collected information can be transmitted to command-and-control infrastructure.
Persistence mechanisms include Windows services and, on Linux, systemd services and reboot-triggered cron jobs. Prometei uses executable packing, obfuscation, legitimate-looking process and service identities, and artifact deletion to hinder analysis and detection. Exchange-focused components remove competing web shells to preserve access. Its communications architecture includes multiple command-and-control servers, Tor and I2P components, and a domain generation algorithm. Encryption is used for selected communications and file transfers, although not every communication channel is encrypted.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft Exchange zero-day exploits (CVE-2021-26858, CVE-2021-27065) allow authenticated hackers to write a file to any path on the vulnerable Exchange server and achieve remote code execution. Botnet operators rely on these bugs to install and execute China Chopper.
Microsoft Exchange zero-day exploits (CVE-2021-26858, CVE-2021-27065) allow authenticated hackers to write a file to any path on the vulnerable Exchange server and achieve remote code execution. Botnet operators rely on these bugs to install and execute China Chopper.
Prometei is now capable of leveraging the “ProxyLogon” exploit for Windows Exchange servers to penetrate the targeted network and drop cryptojacking malware onto users’ machines.
RdpcIip can’t spread to other machines using the stolen credentials, it uses the EternalBlue exploit and sends a shellcode to install and launch the main bot module Sqhost.exe. | Prometei is a modular and multi-stage cryptocurrency botnet that was first discovered in July 2020 which has both Windows and Linux versions.
To use the RDP exploit BlueKeep, the malware uses another component, Bklocal2.exe / Bklocal4.exe | Prometei is a modular and multi-stage cryptocurrency botnet that was first discovered in July 2020 which has both Windows and Linux versions.
Having thus obtained usernames and passwords for computers with MS SQL installed, the attackers used the T-SQL function xp_cmdshell to run several PowerShell scripts and elevated the privileges of the current user by exploiting the CVE-2016-0099 vulnerability. | The parties responsible for its distribution turned out to be the Prometei malware family and a new family called Cliptomaner.
Cisco Talos recently discovered a cryptocurrency-mining botnet attack we're calling "Prometei" ... employing a multi-modular botnet with multiple ways to spread and a payload focused on providing financial benefits for the attacker by mining the Monero online currency.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
RdpcIip reads those files and tries to validate the credentials and use them for spreading across the network
“Prometei” exploite principalement des vulnérabilités connues affectant des services exposés, notamment le Remote Desktop Protocol...
Our telemetry showed three malware families taking advantage of the ProxyLogon vulnerability beginning in March... Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells
The commands can be used as “stand-alone” native OS commands (cmd commands, WMI, etc.)
Chaque machine infectée rejoint un réseau C2, permettant aux opérateurs d’exécuter des commandes
Using the webshell, the attackers launched a PowerShell that was then used to download a payload
RdpcIip reads those files and tries to validate the credentials and use them for spreading across the network
it also changes the following registry key to 1 so the credentials are stored in memory and retrieved using techniques employed by Miwalk.exe: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential
“Prometei” exploite principalement des vulnérabilités connues affectant des services exposés, notamment le Remote Desktop Protocol...
Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells... The China Chopper web shell... continues to be widely used by threat actors in their campaigns to gain remote access to a targeted system.
Exchdefender tries to masquerade as a “Microsoft Exchange Defender”, a non-existent program that masquerades as a legitimate Microsoft product
To harvest credentials, RdpcIip.exe launches another component, Miwalk.exe, a customized version of Mimikatz
wmic ComputerSystem get Model - wmic OS get lastbootuptime - wmic baseboard get product - wmic os get caption
it uses many techniques such as known exploits EternalBlue and BlueKeep, harvesting credentials, exploiting SMB and RDP exploits
Prometei uses different techniques and tools, ranging from Mimikatz to SMB and RDP exploits and other tools that all work together to propagate across the network
Windlver.exe ... is an OpenSSH and SSLib-based software that the attackers have created so they can spread across the network using SSH
Prometei is built to interact with four different command and control (C2) servers which strengthens the botnet’s infrastructure and maintains continuous communications
Prometei is built to interact with four different command and control (C2) servers
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet whose activity increased in the IoT threat landscape during the quarter.
Prometei2
A named malware family identified as one of the principal threats in attacks against Linux SSH servers.
Referenced in supporting material as a botnet exploiting Microsoft Exchange vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.