Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Prometei

115
Global rank
69 infographic chevron month
Month rank
111 infographic chevron week
Week rank
0
IOCs

Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

Botnet
Type
Unknown
Origin
1 March, 2016
First seen
11 September, 2026
Last seen

How to analyze Prometei with ANY.RUN

Type
Unknown
Origin
1 March, 2016
First seen
11 September, 2026
Last seen

IOCs

IP addresses
91.189.91.58
31.56.209.100
185.125.190.56
185.125.190.57
91.189.91.60
91.189.91.64
192.178.183.136
48.209.138.168
23.0.174.97
142.251.150.119
20.190.159.68
23.200.214.115
142.251.127.84
74.178.240.61
23.11.41.157
142.251.20.95
178.105.255.79
2.19.252.163
172.217.118.4
57.153.246.3
Hashes
2bc860efee229662a3c55dcf6e50d6142b3eec99c606faa1210f24541cad12f5
f845be2b7ded6f3e2bbcf2f80c485ae1f23bfad99e534ad4e554f19cbe6342a6
c655d3d4e374fad38313ec4262207b2d7d68a870238f203ef3c33f85e66c8e32
889515367cfc5ba8f8eb99d215ab3ccc65d4ad61d89247264b4019d7cf6cb09c
a8eac752e2d37d7afcc7a48f0c09d8ab2bb737422037465fb43845913d3f58c4
dc43fdfbb5f7e8ecc80353dcd85889c0c08483c99acbce35b3ed8f399c936920
9dbbc9b5d7793425968e42e995226c5f9fe32e502a0a694320a5e838d57c8836
08caefcaed31eb1fe6f0271019897483d2030011d3ac290eabefb2322947d41c
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
c52c62a7c50daf7d3f73ec16977cd4b0ea401710807d5dbe3850941dd1b73a70
d571ef33b0e707571f10bb37b99a607d6f43afe33f53d15b4395b16ef3fda665
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
8223a912160354e05735522fdb339dc59b353ad5d1e4f4cfa94898dc348e748f
8c5fa4b29519d17593e923bc6a9a284df7a6d07fac42f897110b8fb2e0baeef5
af0edb67c2219b803c3eb6c1dee6f2d41a3fe00468a9da8be8ef5056d701abf3
97a4755fe9e653a08969f1933e3db19c712078b227bd5aa6799093abc5a0edc3
c2784e33158a807135850f7125a7eaabe472b3cfc7afb82c74f02da69ea250fe
Domains
p1.feefreepool.net
connectivity-check.ubuntu.com
google.com
clients1.google.com
sb-ssl.google.com
activation-v2.sls.microsoft.com
update.googleapis.com
slscr.update.microsoft.com
chromewebstore.googleapis.com
safebrowsing.googleapis.com
edgedl.me.gvt1.com
clients2.google.com
client.wns.windows.com
nexusrules.officeapps.live.com
go.microsoft.com
www.bing.com
crl.microsoft.com
settings-win.data.microsoft.com
optimizationguide-pa.googleapis.com
login.live.com
URLs
http://connectivity-check.ubuntu.com/
http://clients2.google.com/time/1/current?cup2key=8:74wzndzrqsifzzd9wojqpr6armyrmgqz5gczljbbie0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://178.105.255.79/dota3.tar.gz
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://update.googleapis.com/service/update2/json?cup2key=14:s5imqvd5andr72psxo3xnfq8o3vzlrcoodzmo7jbfxa&cup2hreq=1dcc989871a64e5e085f2df5d088972a6629d7ec35efb7f052e9f607541d32c6
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://optimizationguide-pa.googleapis.com/v1:getmodels?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://optimizationguide-pa.googleapis.com/downloads?name=1679317318&target=optimization_target_language_detection
https://optimizationguide-pa.googleapis.com/downloads?name=1753110098&target=optimization_target_notification_permission_predictions
https://optimizationguide-pa.googleapis.com/downloads?name=1696267841&target=optimization_target_omnibox_url_scoring
https://optimizationguide-pa.googleapis.com/downloads?name=1753110074&target=optimization_target_geolocation_permission_predictions
https://optimizationguide-pa.googleapis.com/downloads?name=1781017313&target=optimization_target_client_side_phishing
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4780
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9604
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11523
comments 0

What is Prometei Botnet?

The Prometei botnet represents one of the most persistent and evolving cryptocurrency mining threats in the cybersecurity landscape. There is evidence that it has been active since 2016, though it was described in 2020.

It is an advanced, multi-component malware system designed to mine cryptocurrency while staying under the radar. Written in multiple programming languages (including Delphi and PowerShell), it supports Windows and Linux platforms and is capable of self-propagation, data exfiltration, and command-and-control (C2) communications.

Its modular architecture allows attackers to dynamically deploy components like credential stealers, backdoors, and lateral movement tools based on the target environment. While its primary goal is cryptojacking, its deep penetration into systems makes it a gateway for broader cyber espionage or sabotage.

The botnet employs domain generation algorithms (DGA) for command and control communications, making it difficult to disrupt its operations through traditional domain blocking methods.

Recent analysis indicates that Prometei has experienced a significant resurgence since March 2025, with updated variants showing enhanced capabilities and more sophisticated anti-analysis features. The malware demonstrates continuous development, with threat actors regularly updating its modules and incorporating new exploitation techniques to maintain effectiveness against modern security measures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Prometei Malware Victimology

Prometei’s victimology is opportunistic rather than highly targeted. It affects a wide range of industries, including finance, insurance, retail, manufacturing, utilities, travel, and construction.

It has been detected across the United States, the United Kingdom, Europe, South America, and East Asia. The botnet exploits unpatched systems, poorly configured servers, and devices with weak security, such as outdated Microsoft Exchange servers or IoT devices with default credentials.

Prometei has infected systems in over 90 countries, with particularly high concentrations observed in Brazil, Indonesia, and Turkey. Recent campaigns have shown over 10,000 systems compromised since November 2022.

What Prometei Botnet Can Do to User Device

Once installed on an endpoint device, Prometei can perform several malicious activities:

  • Cryptocurrency Mining: It hijacks computing resources to mine Monero, often causing significant performance degradation.
  • Credential Theft: It employs modules (e.g. Mimikatz) to harvest login credentials, sometimes using the WDigest protocol to store passwords in plaintext.
  • Data Theft: It can extract sensitive system information, including processor details, OS data, and network configurations.
  • Lateral Movement: It spreads within networks using protocols like RDP, SSH, and SMB.
  • Backdoor Installation: Newer versions include backdoors for persistent access and additional payload deployment.
  • Web Shell Deployment: It can install PHP-based web shells via a bundled Apache web server to execute remote commands.
  • Additional payload download.

How Prometei Malware Threatens Businesses and Organizations

For businesses and organizations, Prometei presents multifaceted threats that extend far beyond cryptocurrency mining. The malware's ability to steal credentials and move laterally through networks means that a single infected system can potentially compromise an entire organizational infrastructure.

The cryptojacking component results in significant financial losses through increased electricity costs, reduced productivity due to system performance degradation, and potential hardware damage requiring replacement. More critically, the backdoor capabilities provide persistent access that can be leveraged for more damaging attacks, including data exfiltration, deployment of additional malware, or ransomware attacks.

The malware's credential harvesting capabilities can result in violations of data protection regulations.

How Does Prometei Botnet Get in the System and Spread?

Similar to other botnets like Mirai and Gafgyt Prometei infects systems through:

  • Exploiting Vulnerabilities: It targets unpatched software, notably Microsoft Exchange Server flaws like ProxyLogon (associated with HAFNIUM attacks).
  • Brute-Force Attacks: It attempts to crack weak administrator passwords via RDP, SSH, or SMB.
  • Phishing Emails: Malicious attachments or links deliver the initial payload.
  • Drive-by Downloads: Compromised websites or fake software updates install the malware.

Once inside a system, it uses spreader modules to propagate across networks, scanning for additional vulnerable endpoints. Its worm-like capabilities enable rapid expansion within poorly secured environments.

How Does Prometei Botnet Function?

Prometei operates through a modular framework, with each component handling specific tasks:

  • Main Module: Executes initial infection and retrieves additional payloads.
  • Spreader Modules: Facilitate lateral movement via RDP, SSH, and SMB.
  • Cryptomining Module: Mines Monero using the infected device’s resources.
  • C2 Communication: Uses a Tor-based C2 server or DGA-generated domains to receive commands and exfiltrate data.
  • Persistence Mechanisms: Creates services, scheduled tasks, or cron jobs to ensure re-infection after system reboots.
  • Web Shell: Deploys a PHP-based web shell for remote command execution. Its self-updating feature and DGA enhance its resilience against takedown efforts.

The botnet utilizes domain generation algorithms to maintain communication with command and control servers, generating new domains dynamically to evade detection and blocking efforts. This technique ensures that even if security teams identify and block known malicious domains, the botnet can continue operating through newly generated communication channels.

Prometei's self-updating capabilities allow it to download and install new modules or updates automatically, ensuring that infected systems remain current with the latest malware variants. This feature contributes to the botnet's longevity and helps it adapt to changing security landscapes and defensive measures.

Prometei Botnet Typical Attack Chain

ANY.RUN’s Interactive Sandbox has seen a variety of Prometei malware samples analyzed by its global community of 500,000 users. Let’s explore one to see how the botnet infiltrates the system.

View analysis

Prometei malware analysis in the Sandbox Prometei Botnet sample detonated in the Sandbox

Prometei starts by making sure there is no older copy of itself on the machine. It searches the running processes for the names uplugplay and upnpsetup with the pgrep command. If it finds either name, it immediately stops those processes with killall5 and pidof. This step clears the way so only the newest version of the malware can run.

When the system is clean, Prometei creates a small file called /etc/CommId. Inside this file it writes a random twelve-character code; in the sample run the code was CPGP332GT4P7AH6F.

Prometei generates code to identify device Prometei generates a code to identify the infected endpoint

Right after that, the malware sends the code to its command-and-control server through an unencrypted HTTP request (http://152[.]36[.]128[.]18/cgi-bin/p.cgi?r=26&i=CPGP332GT4P7AH6F). The attackers use this code to recognize and track the infected computer.

Prometei sends code to c2c server The code gets sent to C2C server

Next, the malware makes sure it will survive a reboot. It drops a new systemd service file called uplugplay.service in the folder /lib/systemd/system/. The service is listed under the friendly name UPlugPlay and is set to run the program /usr/sbin/uplugplay.

Prometei persistence mechanism Part of Prometei persistence mechanism

Prometei copies its own binary into that location, deletes the original dropper, and then runs two shell commands: systemctl enables uplugplay.service and systemctl starts uplugplay.service. These commands turn the service on right away and guarantee it will start automatically whenever the operating system boots.

After installation, the program becomes quiet. It checks whether it was launched with an extra parameter, so it can switch from the installer role to its normal botnet duties. The parameter it expects later is “Dcomsvc”, which would be used like this: /usr/sbin/uplugplay -Dcomsvc. Once everything is in place, Prometei waits in the background for more instructions from its command-and-control server, ready to carry out whatever tasks the attackers send next.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Gathering Threat Intelligence on Prometei malware

Threat intelligence plays a crucial role in defending against Prometei by providing actionable information about the malware's tactics, techniques, and procedures.

Behavioral intelligence describing Prometei's operational patterns helps security teams develop effective detection rules and monitoring strategies. Understanding the malware's lateral movement techniques and persistence mechanisms enables more comprehensive threat hunting activities.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"prometei"

Prometei malware samples found via TI Lookup Prometei Botnet samples recently analyzed in ANY.RUN's Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Prometei Botnet is more than just another cryptominer — it’s a modular, persistent, and evasive malware that undermines enterprise security while silently monetizing your infrastructure. With its stealth tactics, lateral movement, and built-in credential theft, it opens doors to deeper compromise. Preventing Prometei requires rigorous patching, strong authentication, and proactive threat intelligence. By understanding its tactics and staying informed with real-time threat data, organizations can turn the tide against this parasitic threat.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Interlock screenshot
Interlock
interlock
Interlock is a relatively recent entrant into the ransomware landscape. First identified in 2023, it's a multi-functional malware strain used in ransomware-as-a-service (RaaS) operations.
Read More
Remus Stealer screenshot
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
Mirage2FA screenshot
Mirage2FA
mirage2fa
Mirage2FA is a Phishing-as-a-Service toolkit designed to compromise Microsoft 365 accounts and bypass conventional MFA through Adversary-in-the-Middle attacks. It uses malicious HTML, XHTML, and SVG files to deliver JavaScript loaders that connect victims to attacker-controlled phishing infrastructure. The toolkit relays authentication in real time, capturing credentials, 2FA codes, and authenticated session cookies. It also uses browser fingerprinting, WebSockets, obfuscation, and rotating infrastructure to evade detection and maintain access to compromised accounts.
Read More
Raspberry Robin screenshot
Raspberry Robin
raspberryrobin
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
Read More