Prometei is a financially motivated, Russian-speaking cybercriminal threat actor and associated botnet/malware family, assessed not to be nation-state backed. It has been known since at least 2016, was first publicly discovered in July 2020, and has been observed targeting organizations in North America, the United States, the United Kingdom, other European countries, South America, and East Asia across sectors including finance, insurance, retail, manufacturing, utilities, travel, and construction. Reporting noted the operators appeared to avoid infecting former Soviet bloc countries. Prometei is a modular, multi-stage, cross-platform operation with Windows and Linux/Unix variants. Its primary monetization goal is cryptocurrency mining, especially Monero via XMRig-based payloads, but it also supports credential theft, data exfiltration, persistence, lateral movement, and broad remote control of infected systems. Prometei has been described as capable of striking both Windows and Linux systems for cryptocurrency mining, credential theft, and data exfiltration, and later reporting noted new backdoor and self-updating features. Observed initial access and propagation methods include brute-force attacks against MS SQL credentials, abuse of T-SQL xp_cmdshell to execute PowerShell, exploitation of CVE-2016-0099 for privilege escalation, exploitation of Microsoft Exchange vulnerabilities CVE-2021-27065 and CVE-2021-26858 to deploy a China Chopper webshell, SMB and RDP exploitation including EternalBlue and BlueKeep, SSH-based spreading, and SQL/PostgreSQL spreading. The intrusion chain has been described as fully automated in some cases. Prometei malware components include a cross-platform .NET Core/Apphost loader that sends host information to command-and-control infrastructure and downloads miner payloads and configuration; the main bot modules zsvc.exe and sqhost.exe, with sqhost.exe providing backdoor functionality; ExchDefender.exe, which maintains execution as a service and deletes Exchange webshells to keep out competing intruders; SearchIndexer.exe as an XMRig-based miner; RdpcIip.exe for credential harvesting and network spreading; Miwalk.exe, a customized Mimikatz used to dump credentials; Nethelper2.exe and Nethelper4.exe for SQL Server and PostgreSQL propagation; and Windrlver.exe for SSH spreading using OpenSSH and stolen or brute-forced credentials. Prometei has also been associated with installation of the Purple Fox Trojan and the Prometei backdoor during attacks. Operators have used cmd.exe, wmic.exe, and other administrative tooling during post-compromise activity, and have established persistence through service creation and registry modifications. Cybereason assessed that beyond cryptomining, Prometei enables follow-on abuse including data theft, additional malware deployment, or resale of access. Known alias in the provided content: Prometei.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware
the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates a modular botnet for cryptocurrency mining, credential theft, and data exfiltration across Windows and Linux systems.
Prometei is described as a backdoor-enabled cryptomining operation distributing XMRig, using brute-force attacks against MS SQL servers, executing PowerShell via xp_cmdshell, exploiting CVE-2016-0099 for privilege escalation, and deploying on both Windows and Linux servers.
Financially motivated cybercrime group operating the Prometei botnet for Monero cryptomining, credential harvesting, lateral movement, and maintaining stealthy backdoor access across Windows and Linux environments.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.