Prometei is a modular, multi-stage cryptocurrency-mining malware family and botnet primarily associated with Monero mining, with mature Windows and Linux variants and evidence of continuous development since at least 2016. It is financially motivated and has been widely assessed as operated by Russian-speaking cybercriminals rather than a nation-state actor. Victimology is largely opportunistic across regions and sectors, including finance, insurance, retail, manufacturing, utilities, travel, construction, and other enterprise environments.
Beyond cryptomining, Prometei provides broad post-compromise control. Its core functionality includes remote command execution, system reconnaissance, credential harvesting, payload download and update, persistence, and lateral movement. Windows variants have used customized credential-dumping components derived from Mimikatz, validated and reused stolen credentials, and attempted brute-force authentication with embedded username and password lists. Observed Linux variants collect host profiling data such as processor, motherboard, operating system, uptime, and kernel details, and support command sets for execution, file transfer, mining control, and host interrogation. Some versions also support anonymized communications through Tor or I2P, domain-generation logic, and self-updating mechanisms to improve resilience and evasion.
Prometei has repeatedly been observed exploiting exposed or vulnerable enterprise services for initial access and propagation. Documented intrusion paths include exploitation of Microsoft Exchange ProxyLogon-era vulnerabilities, abuse of weak or default RDP credentials, brute-forcing of MS SQL credentials, and automated spreading through SMB, RDP, SSH, SQL Server, and PostgreSQL services. For lateral movement and propagation, Prometei has used stolen credentials, brute force, PsExec, WMI, EternalBlue, and BlueKeep, and Linux-targeting components have been used to spread over SSH and to deploy payloads onto Unix-like hosts.
Persistence and defense evasion are central to the malware’s design. Windows infections commonly establish a service named UPlugPlay for durable execution, while Linux infections have used systemd services and cron-based reboot persistence while masquerading as legitimate system components. Prometei operators have also deployed auxiliary modules to preserve exclusive access by removing competing web shells from compromised Exchange servers or blocking other brute-force sources with firewall rules. Additional observed behaviors include audit policy manipulation, firewall rule changes, and security product exclusions or disabling activity in some campaigns.
Prometei is best characterized as a worm-capable cryptomining botnet with backdoor and credential-theft functionality. Its modular architecture allows operators to combine mining, credential theft, reconnaissance, lateral movement, and follow-on payload delivery, making it a broader enterprise intrusion platform rather than a simple miner alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
RdpcIip can’t spread to other machines using the stolen credentials, it uses the EternalBlue exploit and sends a shellcode to install and launch the main bot module Sqhost.exe. | Prometei is a modular and multi-stage cryptocurrency botnet that was first discovered in July 2020 which has both Windows and Linux versions.
the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware | Prometei is a modular and multi-stage cryptocurrency botnet that was first discovered in July 2020 which has both Windows and Linux versions.
Our telemetry showed three malware families taking advantage of the ProxyLogon vulnerability beginning in March: the coinminer LemonDuck was sighted first, quickly followed by the ransomware BlackKingdom, then the Prometei botnet.
the attackers exploited recently published Microsoft Exchange vulnerabilities (CVE-2021-27065 and CVE-2021-26858) in order to penetrate the network and install malware | Prometei is a modular and multi-stage cryptocurrency botnet that was first discovered in July 2020 which has both Windows and Linux versions.
To use the RDP exploit BlueKeep, the malware uses another component, Bklocal2.exe / Bklocal4.exe | Prometei is a modular and multi-stage cryptocurrency botnet that was first discovered in July 2020 which has both Windows and Linux versions.
Having thus obtained usernames and passwords for computers with MS SQL installed, the attackers used the T-SQL function xp_cmdshell to run several PowerShell scripts and elevated the privileges of the current user by exploiting the CVE-2016-0099 vulnerability. | The parties responsible for its distribution turned out to be the Prometei malware family and a new family called Cliptomaner.
Cisco Talos recently discovered a cryptocurrency-mining botnet attack we're calling "Prometei" ... employing a multi-modular botnet with multiple ways to spread and a payload focused on providing financial benefits for the attacker by mining the Monero online currency.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
RdpcIip reads those files and tries to validate the credentials and use them for spreading across the network
“Prometei” exploite principalement des vulnérabilités connues affectant des services exposés, notamment le Remote Desktop Protocol...
Our telemetry showed three malware families taking advantage of the ProxyLogon vulnerability beginning in March... Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells
The commands can be used as “stand-alone” native OS commands (cmd commands, WMI, etc.)
Chaque machine infectée rejoint un réseau C2, permettant aux opérateurs d’exécuter des commandes
Using the webshell, the attackers launched a PowerShell that was then used to download a payload
RdpcIip reads those files and tries to validate the credentials and use them for spreading across the network
it also changes the following registry key to 1 so the credentials are stored in memory and retrieved using techniques employed by Miwalk.exe: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest\UseLogonCredential
“Prometei” exploite principalement des vulnérabilités connues affectant des services exposés, notamment le Remote Desktop Protocol...
Leveraging the ProxyLogon vulnerability allowed the threat actors behind BlackKingdom, Prometei, and LemonDuck to execute Chopper web shells... The China Chopper web shell... continues to be widely used by threat actors in their campaigns to gain remote access to a targeted system.
Exchdefender tries to masquerade as a “Microsoft Exchange Defender”, a non-existent program that masquerades as a legitimate Microsoft product
To harvest credentials, RdpcIip.exe launches another component, Miwalk.exe, a customized version of Mimikatz
wmic ComputerSystem get Model - wmic OS get lastbootuptime - wmic baseboard get product - wmic os get caption
it uses many techniques such as known exploits EternalBlue and BlueKeep, harvesting credentials, exploiting SMB and RDP exploits
Prometei uses different techniques and tools, ranging from Mimikatz to SMB and RDP exploits and other tools that all work together to propagate across the network
Windlver.exe ... is an OpenSSH and SSLib-based software that the attackers have created so they can spread across the network using SSH
Prometei is built to interact with four different command and control (C2) servers which strengthens the botnet’s infrastructure and maintains continuous communications
Prometei is built to interact with four different command and control (C2) servers
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet whose activity increased in the IoT threat landscape during the quarter.
Prometei2
A named malware family identified as one of the principal threats in attacks against Linux SSH servers.
Referenced in supporting material as a botnet exploiting Microsoft Exchange vulnerabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.