A UK construction firm identified a Prometei botnet infection on a Windows Server after attackers likely gained initial access by guessing weak/default RDP credentials. eSentire’s Threat Response Unit attributed the activity to the Russian-linked Prometei operation (active since 2016), which is commonly associated with Monero cryptomining but also supports credential theft and remote control. For persistence, Prometei was observed installing a service named UPlugPlay and deploying sqhost.exe, then downloading an encrypted main payload (zsvc.exe) and collecting host/system details using native Windows tooling while routing C2 traffic through Tor.
The intrusion also included post-compromise credential access behavior consistent with Mimikatz usage (reported as miWalk) to harvest passwords across the environment, plus evasion techniques such as checking for mshlpda32.dll and performing decoy actions when analysis/sandbox conditions are suspected. Prometei additionally attempted to “lock in” its access by deploying netdefender.exe to block other unauthorized access attempts, effectively monopolizing the compromised host. eSentire also released analysis tooling intended to help researchers reverse and track the malware, reinforcing the operational takeaway that exposed RDP and poor credential hygiene remain high-probability entry points for commodity-to-advanced botnet operators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By early February 2026, eSentire released technical analysis, YARA rules, and Python utilities to help researchers unpack and detect Prometei, while recommending stronger passwords, MFA, patching, and improved RDP monitoring.
On the compromised host, Prometei gathered system information, used Mimikatz-based tooling to harvest passwords, communicated through TOR, and deployed a module such as netdefender.exe to block other attackers from accessing the system.
After gaining access, the malware established persistence through a Windows service such as UPlugPlay, dropped components including sqhost.exe, and downloaded or decrypted its main payload, identified as zsvc.exe.
In January 2026, a UK construction firm discovered an intrusion on a Windows Server that eSentire assessed likely began through Remote Desktop Protocol access using weak or default credentials.
Prometei has been active since 2016 as a Russian-linked botnet focused on Monero cryptomining, while also supporting credential theft, remote control, and lateral movement capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.