Cybereason reported incident response cases in which the Prometei botnet compromised organizations in North America by exploiting Microsoft Exchange vulnerabilities CVE-2021-27065 and CVE-2021-26858 for initial access. After entry, the operators deployed a modular malware framework that included components such as sqhost.exe, rdpcIip.exe, ExchDefender.exe, Miwalk.exe, Nethelper, Windrlver.exe, and an XMRig-based SearchIndexer.exe, enabling both Monero cryptomining and persistent access.
Research from Cisco Talos and CUJO AI shows Prometei has long operated as a multi-stage, cross-platform botnet with Windows and Linux variants, expanding well beyond mining into credential theft, reconnaissance, lateral movement, and backdoor activity. The malware spreads through stolen credentials, brute force, SMB/RDP, SSH, SQL, and exploits including EternalBlue and BlueKeep; investigators assessed the operators as financially motivated, Russian-speaking cybercriminals whose infrastructure and samples indicate the botnet has been active since at least 2016 and continues to evolve.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Cybereason published a report detailing Prometei infections tied to Exchange exploitation, describing the botnet's modular tooling, credential theft, lateral movement, and cryptomining activity across multiple regions and industries.
CUJO AI published research focused on the Linux variant of Prometei, adding technical detail on the botnet's cross-platform capabilities.
Cisco Talos published research on the Prometei botnet and its Monero-mining operations, documenting the threat as an active malware campaign.
Cybereason assessed from Prometei infrastructure and malware samples that the botnet has existed since at least 2016 and has continued to evolve over time.
Cybereason investigated incident response cases in which Prometei operators compromised organizations in North America by exploiting Microsoft Exchange vulnerabilities CVE-2021-27065 and CVE-2021-26858, deploying a China Chopper webshell and follow-on malware.
Microsoft listed CVE-2021-26858 in its Security Update Guide, establishing public disclosure of one of the Exchange vulnerabilities later cited in Prometei intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybereason.com
Open sourcecujo.com
Open sourceblog.talosintelligence.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.