Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Prometei

118
Global rank
73 infographic chevron month
Month rank
63 infographic chevron week
Week rank
0
IOCs

Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

Botnet
Type
Unknown
Origin
1 March, 2016
First seen
23 August, 2026
Last seen

How to analyze Prometei with ANY.RUN

Type
Unknown
Origin
1 March, 2016
First seen
23 August, 2026
Last seen

IOCs

IP addresses
91.189.91.97
185.125.190.57
185.125.190.56
185.125.190.101
91.189.91.96
40.126.31.2
74.179.77.164
48.209.133.15
172.211.123.248
20.190.159.4
48.192.1.65
88.221.169.205
48.209.6.48
57.153.246.3
74.178.240.61
23.11.40.157
88.221.169.152
2.16.241.19
172.211.123.250
20.190.160.3
Hashes
4377e894b3e7956b74d467118164b7023e9b0f0f4c151e464d00991e30f924ac
f9120c06aad5aa4add1b646456199fd34b4fa72c6eb8ba4d37d85a59d7cac478
769d295254984b910120e073bc7cdafa15a1c1310d513a1c2924c7a21d332db3
5279f80f139fcf962ac44abc4b79b67d14807c8f5a6d9ec8e9e3f7023532961d
a87b3c39d9356009477129f7228d393f121cfc78f94e564766201b7e70c8e94c
df719ce7c80a625bced0d141cbccae54650b14c56c3b7afc06afa0fb8c30f72e
ce357dc9d96cbb6933f7895d5fee9052b72733c2db9fc32b1555761b1bd0c277
1de0ece47647946782f790d4aa8e74295df8db96bc0e2442337edf320e2c76a8
b05c27574c61a7b79ee20aa6e5fa00ddb30027d7063bd587fd468f41845b386b
d8120ef961aa32d03f2623c07a801d07ef7764a2a0da1d9c79678d91fe0b1f7a
c8d2db90cc0c35b74b3f18cfd9c2f54d298e6fec5a25eaa61786d5b422e39c3e
41d927607c18b7a1f93c738ee443072fca65c7bc963dc2247e34440e652fafe3
e6af45ceffbdc707aae14b392236443ffce0cbdf89f5d3e5a6e4d0088c2461c8
c3fa96a0a213bcd2abdd386feedd4169ed6d172b7cd497880b1d0cc4c58a78db
3d49444c7f58ccbd6ba93587fce2420f1e1775cfa8592b259d4a921b38e42533
3e9b22ca450a78aa2ee279292bc6f73fe6d1a575d8c9035c8fac36740cc28bd3
805a8845084317325a6af3fd3c415b9a6140d0b45e027568b4852aac320097c6
451341ba176d94035d89bde4ba2aac87fafa80d70195c07f978c8753d3a42d15
216edb98a7cda66967c0bb3fcc26188887dcc95d301579e310231bb8cd3a3c0f
7812d8f5ad47a32e71540391771c796802193a36b325c09c3ff4d5f03c321eb2
Domains
connectivity-check.ubuntu.com
google.com
www.microsoft.com
go.microsoft.com
settings-win.data.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
activation-v2.sls.microsoft.com
crl.microsoft.com
client.wns.windows.com
ocsp.digicert.com
licensing.mp.microsoft.com
canonical-lgw01.cdn.snapcraftcontent.com
cdn.fwupd.org
api.snapcraft.io
r.msftstatic.com
clients2.google.com
ogads-pa.clients6.google.com
sb.scorecardresearch.com
URLs
http://connectivity-check.ubuntu.com/
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/waas/featuremanagement?isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&currentbranch=vb_release&accountfirstchar=&activationchannel=retail&oemmodel=dell&flightring=retail&attrdataver=186&installlanguage=en-us&osuilocale=en-us&webexperience=1&flightingbranchname=&chassistypeid=1&osskuid=48&app=cdm&installdate=1661339444&appver=&osarchitecture=amd64&defaultuserregion=244&telemetrylevel=1&osversion=10.0.19045.4046&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://licensing.mp.microsoft.com/v7.0/licenses/content
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2227
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 6651
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10099
comments 0

What is Prometei Botnet?

The Prometei botnet represents one of the most persistent and evolving cryptocurrency mining threats in the cybersecurity landscape. There is evidence that it has been active since 2016, though it was described in 2020.

It is an advanced, multi-component malware system designed to mine cryptocurrency while staying under the radar. Written in multiple programming languages (including Delphi and PowerShell), it supports Windows and Linux platforms and is capable of self-propagation, data exfiltration, and command-and-control (C2) communications.

Its modular architecture allows attackers to dynamically deploy components like credential stealers, backdoors, and lateral movement tools based on the target environment. While its primary goal is cryptojacking, its deep penetration into systems makes it a gateway for broader cyber espionage or sabotage.

The botnet employs domain generation algorithms (DGA) for command and control communications, making it difficult to disrupt its operations through traditional domain blocking methods.

Recent analysis indicates that Prometei has experienced a significant resurgence since March 2025, with updated variants showing enhanced capabilities and more sophisticated anti-analysis features. The malware demonstrates continuous development, with threat actors regularly updating its modules and incorporating new exploitation techniques to maintain effectiveness against modern security measures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Prometei Malware Victimology

Prometei’s victimology is opportunistic rather than highly targeted. It affects a wide range of industries, including finance, insurance, retail, manufacturing, utilities, travel, and construction.

It has been detected across the United States, the United Kingdom, Europe, South America, and East Asia. The botnet exploits unpatched systems, poorly configured servers, and devices with weak security, such as outdated Microsoft Exchange servers or IoT devices with default credentials.

Prometei has infected systems in over 90 countries, with particularly high concentrations observed in Brazil, Indonesia, and Turkey. Recent campaigns have shown over 10,000 systems compromised since November 2022.

What Prometei Botnet Can Do to User Device

Once installed on an endpoint device, Prometei can perform several malicious activities:

  • Cryptocurrency Mining: It hijacks computing resources to mine Monero, often causing significant performance degradation.
  • Credential Theft: It employs modules (e.g. Mimikatz) to harvest login credentials, sometimes using the WDigest protocol to store passwords in plaintext.
  • Data Theft: It can extract sensitive system information, including processor details, OS data, and network configurations.
  • Lateral Movement: It spreads within networks using protocols like RDP, SSH, and SMB.
  • Backdoor Installation: Newer versions include backdoors for persistent access and additional payload deployment.
  • Web Shell Deployment: It can install PHP-based web shells via a bundled Apache web server to execute remote commands.
  • Additional payload download.

How Prometei Malware Threatens Businesses and Organizations

For businesses and organizations, Prometei presents multifaceted threats that extend far beyond cryptocurrency mining. The malware's ability to steal credentials and move laterally through networks means that a single infected system can potentially compromise an entire organizational infrastructure.

The cryptojacking component results in significant financial losses through increased electricity costs, reduced productivity due to system performance degradation, and potential hardware damage requiring replacement. More critically, the backdoor capabilities provide persistent access that can be leveraged for more damaging attacks, including data exfiltration, deployment of additional malware, or ransomware attacks.

The malware's credential harvesting capabilities can result in violations of data protection regulations.

How Does Prometei Botnet Get in the System and Spread?

Similar to other botnets like Mirai and Gafgyt Prometei infects systems through:

  • Exploiting Vulnerabilities: It targets unpatched software, notably Microsoft Exchange Server flaws like ProxyLogon (associated with HAFNIUM attacks).
  • Brute-Force Attacks: It attempts to crack weak administrator passwords via RDP, SSH, or SMB.
  • Phishing Emails: Malicious attachments or links deliver the initial payload.
  • Drive-by Downloads: Compromised websites or fake software updates install the malware.

Once inside a system, it uses spreader modules to propagate across networks, scanning for additional vulnerable endpoints. Its worm-like capabilities enable rapid expansion within poorly secured environments.

How Does Prometei Botnet Function?

Prometei operates through a modular framework, with each component handling specific tasks:

  • Main Module: Executes initial infection and retrieves additional payloads.
  • Spreader Modules: Facilitate lateral movement via RDP, SSH, and SMB.
  • Cryptomining Module: Mines Monero using the infected device’s resources.
  • C2 Communication: Uses a Tor-based C2 server or DGA-generated domains to receive commands and exfiltrate data.
  • Persistence Mechanisms: Creates services, scheduled tasks, or cron jobs to ensure re-infection after system reboots.
  • Web Shell: Deploys a PHP-based web shell for remote command execution. Its self-updating feature and DGA enhance its resilience against takedown efforts.

The botnet utilizes domain generation algorithms to maintain communication with command and control servers, generating new domains dynamically to evade detection and blocking efforts. This technique ensures that even if security teams identify and block known malicious domains, the botnet can continue operating through newly generated communication channels.

Prometei's self-updating capabilities allow it to download and install new modules or updates automatically, ensuring that infected systems remain current with the latest malware variants. This feature contributes to the botnet's longevity and helps it adapt to changing security landscapes and defensive measures.

Prometei Botnet Typical Attack Chain

ANY.RUN’s Interactive Sandbox has seen a variety of Prometei malware samples analyzed by its global community of 500,000 users. Let’s explore one to see how the botnet infiltrates the system.

View analysis

Prometei malware analysis in the Sandbox Prometei Botnet sample detonated in the Sandbox

Prometei starts by making sure there is no older copy of itself on the machine. It searches the running processes for the names uplugplay and upnpsetup with the pgrep command. If it finds either name, it immediately stops those processes with killall5 and pidof. This step clears the way so only the newest version of the malware can run.

When the system is clean, Prometei creates a small file called /etc/CommId. Inside this file it writes a random twelve-character code; in the sample run the code was CPGP332GT4P7AH6F.

Prometei generates code to identify device Prometei generates a code to identify the infected endpoint

Right after that, the malware sends the code to its command-and-control server through an unencrypted HTTP request (http://152[.]36[.]128[.]18/cgi-bin/p.cgi?r=26&i=CPGP332GT4P7AH6F). The attackers use this code to recognize and track the infected computer.

Prometei sends code to c2c server The code gets sent to C2C server

Next, the malware makes sure it will survive a reboot. It drops a new systemd service file called uplugplay.service in the folder /lib/systemd/system/. The service is listed under the friendly name UPlugPlay and is set to run the program /usr/sbin/uplugplay.

Prometei persistence mechanism Part of Prometei persistence mechanism

Prometei copies its own binary into that location, deletes the original dropper, and then runs two shell commands: systemctl enables uplugplay.service and systemctl starts uplugplay.service. These commands turn the service on right away and guarantee it will start automatically whenever the operating system boots.

After installation, the program becomes quiet. It checks whether it was launched with an extra parameter, so it can switch from the installer role to its normal botnet duties. The parameter it expects later is “Dcomsvc”, which would be used like this: /usr/sbin/uplugplay -Dcomsvc. Once everything is in place, Prometei waits in the background for more instructions from its command-and-control server, ready to carry out whatever tasks the attackers send next.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Gathering Threat Intelligence on Prometei malware

Threat intelligence plays a crucial role in defending against Prometei by providing actionable information about the malware's tactics, techniques, and procedures.

Behavioral intelligence describing Prometei's operational patterns helps security teams develop effective detection rules and monitoring strategies. Understanding the malware's lateral movement techniques and persistence mechanisms enables more comprehensive threat hunting activities.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"prometei"

Prometei malware samples found via TI Lookup Prometei Botnet samples recently analyzed in ANY.RUN's Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Prometei Botnet is more than just another cryptominer — it’s a modular, persistent, and evasive malware that undermines enterprise security while silently monetizing your infrastructure. With its stealth tactics, lateral movement, and built-in credential theft, it opens doors to deeper compromise. Preventing Prometei requires rigorous patching, strong authentication, and proactive threat intelligence. By understanding its tactics and staying informed with real-time threat data, organizations can turn the tide against this parasitic threat.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

WarmCookie screenshot
WarmCookie
badspace
WarmCookie is a backdoor malware that cyber attackers use to gain initial access to targeted systems. It is often distributed through phishing emails, frequently using job recruitment lures to entice victims into downloading and executing the malware.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More