Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Prometei

109
Global rank
86 infographic chevron month
Month rank
68 infographic chevron week
Week rank

Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

Botnet
Type
Unknown
Origin
1 March, 2016
First seen
7 October, 2026
Last seen

How to analyze Prometei with ANY.RUN

Type
Unknown
Origin
1 March, 2016
First seen
7 October, 2026
Last seen

IOCs

IP addresses
185.125.190.56
151.101.194.49
91.189.91.97
91.189.91.96
8.8.8.8
103.176.111.176
185.125.190.57
185.125.190.99
91.189.91.64
91.189.91.58
185.125.188.60
91.199.133.133
185.125.188.57
185.125.190.100
185.125.188.61
185.125.188.58
91.189.91.101
91.189.91.157
48.209.138.168
48.192.1.65
Hashes
56c82365edb1088db0c0c18905e3b5f9392582a05bb8372be1b7a78926ad4a1f
b05c27574c61a7b79ee20aa6e5fa00ddb30027d7063bd587fd468f41845b386b
d8120ef961aa32d03f2623c07a801d07ef7764a2a0da1d9c79678d91fe0b1f7a
d2bd32d598b4d9febebc2b26d0bfa6ff2d7e06282530dc7f9d348688089f33c2
c339f812d933e8edfb280697f4161d7850b37c30efc4e925789542140f14c188
bd432bbfc0cff013a1dc038a327cc094352e8bc209dd03de2a1402b77b20c10d
6e0399bbd6a3b310aaf979eaf48498842ddbb89a73280110e90b77408349a171
fad39de0b458050333c85c0f2cefea5b7dac3007683e1e61fc3caf40f7891145
eb6ffd791b5299383f0e4ee65322b97cce9e883b18b84380d2e16554974916a7
154dd1fccec8242a54fc8828d5a9f6543b827f85f25d77b430fc61d6c74a78cb
8602528ad3d983e13b953813b416f1bb1d4a38adb94ed9a20c823c72ccbb5c7a
397c4f63865f3282e6ce70acae59d91cff87912d152affbd2ffee7ff77a88227
13d74ebed58a254e0c1d7d0be4620a8276ad8bcd4d28e30f587656f621aee8ae
2350ab783a89b21eeb077365613814146f4bbf647a51f9edece43cfe70445feb
71aca864c28eda352580e3f5cbb09bc29e1de1bc91d0407aeb14e69c5767bd79
615eda603c1747b11d0fdb9f670eeed8d6344cf443d890e988050842809ba8c6
4a14b3c716b8722a12fa58f08e5b4922657023b2a0f6e490bf8d28a496f33cec
27de1f2c0b72ef8e18cccb4476d986dcf42712cf31230116b9bfdc5b33848708
f43e44009d35dd253fae8c0a5c36a3bc53d93a468d6e4f068ab3e9e46478b05f
4ffe31c01fc8ccdbd0905b3ebec108657e9009dfdaaa385b7f383651a683111d
Domains
cdn.fwupd.org
connectivity-check.ubuntu.com
3.100.168.192.in-addr.arpa
google.com
6.100.168.192.in-addr.arpa
4.100.168.192.in-addr.arpa
api.snapcraft.io
dashboard.snapcraft.io
canonical-bos01.cdn.snapcraftcontent.com
activation-v2.sls.microsoft.com
crl.microsoft.com
www.microsoft.com
settings-win.data.microsoft.com
5.100.168.192.in-addr.arpa
8.100.168.192.in-addr.arpa
go.microsoft.com
slscr.update.microsoft.com
ecs.office.com
fe3cr.delivery.mp.microsoft.com
self.events.data.microsoft.com
URLs
http://connectivity-check.ubuntu.com/
http://103.176.111.176/cgi-bin/p.cgi?r=26&i=h8p1ncmzh17m239w
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1rrmxe0b0fuuxhlsmzryuertg9rz1exswzyrlzrwmdfudrfmvnsvmnjsfldog5rt2lzz2xuee9ydfnrzzfws0jfnja1vwi1nzfgk1dobfnxk2wwahrxagcyk0thegpeu3p1dkk4ntduslvqa2j5sjzqawi3rhbvznfitlrwwjizymfmzw9mbytjy29ts0zqyzdfa0fjrnhjcehxvk03tdjcrmlou2rsshpxbg04ngttwk8vunzqvk9rwtnyenbzrs9rwuswd2nqshlxqxjtddlpy2zzu1dhevbnazjyynpjtk9iu3p0sxplofdmwexzcdi4mjhqyk1aethpmtlyvvvxehnycfjlvhhdme5loxa5evdarmj3kzdxoejfanpnnxzzvnves0vzsxdzbvriovu0y1zkdnphcnbzoue4r1hgdljucgjwuwvtalhmajbouwzjtvqxmxdvu2gwa1zsrkjlamrgsxfxncs0zw40zkdmbmtkbwzwnmhocms3shlgakjzy1bmcdrobjn6nxfkm1duogflrfhxl0vknwevaevzqwpry2xkrhy4wxh5d2tabzu2y0hsr3rpdezmmulrz0rjnhjjagjemhzlvwvxdgqyb1dsvtdqouxkbwfarm02smw1nvrotxhyvkxjt1nkn3jlbxdnv3boww5injlqzc9sslgrq0fuuzvbnjiwqzzcy3myddz2mw9zsfrautnoynq1qtv2bz19&i=h8p1ncmzh17m239w&h=e$rssovq1yw3u=&enckey=jsxesfcmvklnhzf4koym47ym+tpnd/ue7a1wxhzmgyevlfn9spag+t4khl+fq1ymj1vjlhanrkg+cik3okkprxycjofgohyqqsr2bml6vnhlmqynobeehgbik29z/dwgjh8afaxklif8ktn6qy1wc1kknrctkkhcg75+tyunhxu=
http://103.176.111.176/cgi-bin/p.cgi?r=29&i=209h14369k03y7v2
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1mxwnpvuklnbxzqztg1dghnati3r2dznwnveuzpmvrenkdpww03nnuruzyvmcs4k2fswdfjy3rtr1r5nvduntrxcwhbcda0nnlib1hvbuzzdxpteejvte5nsxzld0vdnjazchlubmdubggzauh6s25ermc5ttvssndsc3ziwwnezuzzbvhialzny2d1wk1zbhixrkrkrzbkbgl5uudldfjgcwninzzoazjndgq5vvj4nez5auldy2nuret0djlhstvqq3plzuxbvthav1cvwfdcekhlatm2uhnhzwzovwhdvg5fduz6c0vdckfrrgjgvhlgsxhhzhdsvdz2r3fpsglsu2zvrkxlnwzboes2wehxegfqes9vnfdlr3lnlzhxwk9kq1k4nnlnwitodvdza0pjunnzcvkxmxvwme5ysei0t3hxtnmxandgyvvnnu9wwxl6sgfbskzvzfh6wxjkoe05k1dtz0xnndlmdjbzovrnm3j0bnr4cvvlbdz4ntfoq1d6wwzuuwwru3dtlzfib0x0yk1xt2tzv0firfdvmxg2rzrmwkvfszc3u0jjoufrv0nqm2hcmky4nxy0vtjcdwe1qxj5ykmydmc2emhasxhou0nib3bicexlatfrs09dmefibzhtew1pnun1sevrc1oxb25qzjjwvtlnavvlnzg0uejtdefcbxblexhvbfh0mvdpces1nwcrqxo2nhh3mnlzcvj6md19&i=209h14369k03y7v2&h=e$rstndzzleog=&enckey=m7awi0e9dfwwggk4cd7qhzhfkwfznsjmrnp7wmekarzwn1kg32e9bee86myrembpol9qfldlx90oyjwzmnj3zwdgswiyove7ods1efc7gnnxgll1mfx6jivyr+xtl4hywtyvh+wec8yprnn4a/vucz2fslvlmxnppb2elm0vkl8=
http://103.176.111.176/cgi-bin/p.cgi?r=35&i=d39ql5jf368438b3
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1rkc3dorwjwswe5d2hguwlrbzu5zznjtjcxek1lb1zkaelidwllumhyrgjvnkz0qlfzr3krugc5uklqow1iavaznec5znrtshbhz0xeykzyt1hbq1zjuwrtownxetb1dvhnnzewl1nqywrtngpol0fznmozqtvuuethoezbwkdazjiwwgjtowl5vvhrtwkwl2fmrk9jetduclnvs0g0odhlzw1soghacjzwrc9cl3zed2vlbte4zhbgcgjqqks4mvhtdwhuy2fom243y055tejezzjmk3dxevm0t3nluy9vveqwzzi5tkr3adjyvjjnue9rnmjilzvvdi9mntdsqtg3qjlzdhpmvxiwazfqdm14ugjmzty1vznjwgx0a1rrrgxns0piwgfsqunuagxlbvv4oeliym54l3prqlkys0i5ew5ovxq3nxu4u0plave0a25ia3jxsgvzk3dknghyq2kwz29tnefen3jqwjzxngnvwu1zbgd4eervdxzud3avsxrhcexsulfjduvwdw90yjbqdujby2pts3pib3oxvvjyb1lhanpemwxzqkjhk2m5yujbu0vjqtrzwjdhew84nw5zm0xzvwf4ttq1ynhiu3vjmelirmpydtryvxryty9qnngxt2dzmth4t2l3q1hqanvxwjlozw5odgdos3zgslfnujfbz2tsb1hjqitsedzxetzxmlv0uda3vlazcfo1mhbicty0dz19&i=d39ql5jf368438b3&h=e$rssl2waenxm=&enckey=wg0r+8qp9jpbrl94meqq3gusws2vl9uwa+4hxhhkd+xip1aj0upzlynkn7ippmotevphebxeapnnq2/kuyq9+tjjyycclhex1x0kfzpqp3kqj5bl0ijsb0gzbf6veg1kesrdl7vpgeppmy0kznvnqx5e3exrskhsizxidknstvi=
http://103.176.111.176/cgi-bin/p.cgi?r=24&i=byham67yzyy3g30n
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1fkadrqrtfxyjvlevo0uvozmkrqqxhidg0zunnbl2n2revhogptejvuzfvytee5mnjldwn3wvjql09rc3hrnxlkn2lzbw4rzgv2afkzoxzmtfd3sg4rm2q1cndlr0rnwjzvvth6zmpyrm8ycehyl3e2t3q5enuxagdcuxrpuvdeewz0c0pmngtez1loowc2skrabs9ls2zmtguwd2zwrevqnhvzu1rmvs9xl1nhofppee9xdnjvrmvrttrxu2s5y0rom21sr3byz0thtjj3zk5ewkdamw1pr3lctfbuq0wwakfoc3fjng1wdwv1ofh2dfl4rhhgsdlqruxgb05jmwmxbmnumfdxvkffrlblkytucjlxvhi0vkpycupismd3zk1rudn3avjsvwdosfbxtdqrowk5a0w5ytrizgg1meowmtvqqnbemtgzv0npvjl4mnpnde8xdnpstlnrunb0v2jeefg4revhm1luzhhkrtfmredjzuxxzitqzdhstno1avdsoenrwlftytl5sdjhl0jhrel6zxfja3nacurfuktay2dvdfz3t1fwsexhtmn4rmdnnjljshrvaw1gthjiagj0a0pbanznr3exbk9yzhlzbu9ym2xzvk1jcy9kunflejy0ulpusnrzohnet1ozug9yvu5jn0dtz1ptcfm2dvbowjlxmi9uzhphvda1zgzgtvg3dknhshjnywvjevbjms8rbmw2st19&i=byham67yzyy3g30n&h=e$rsrx74uejoc=&enckey=xqzcyqpnctg31ttuzv2l7ejilm8rxvo9gcmduv4gh+xztdpd15qa6mypnxzbxwrwkwmxjn2ap5n3fooys0krmo+n9dmxikgxbbit+cgjnqkvhit3/of9qdruvxj00rixi2wiosh5lnehpx0p06rh24t3phhhfeihkifyfhaxwvu=
http://103.176.111.176/cgi-bin/p.cgi?r=33&i=5twu765jrpk1m86a
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1nkqwc2tkjsv1v2m3dbzvjetmrrww9paxjhqkfkwe1vcldsntdybnbrsu0ravrmuurvrxq4nnjtr1nicwcxm0mzsjb0k08rzg41s3bgc25rtwmytvhrngpmr2njalg3be90zndtquvtzxaxzwfnwxhbrnrwsupscdjmbgz3rthpsxpuvhz1ewz5t3z5nmxcrzfemnovsjdootg3wko1n0luru04tu1yu3hksm9ewvfovej4vu9jqu9smmpeoevlvxznvmluk1ezb2rirhzab1dycknvrenzbmlbvtv3rthunlzjywg2yuhestc1c0gzte9qstbwn1hxzhz5del4txgvt1bzagnbvdbgvkfjbhzpr01nqm4vsfdvv3dlavpirg55tuywai9ytkzxzuu3zxqyuuryqwnwuxvzqwtyddbsrdzhs0y2zze5oxlcv2fkbvrkeny3zdnyvlnpzdjzb2lvdjdowna4adazmlvnaeu3u09ez0k2zes2rgrybfmwn1rhsgfrstjdmhvtenzsq21kylu2k1dhdy9na3g5tlhqanr2tdbmt256bjfwbxfstwpksnpjyvo0wdfychyxrelzwvznuzvervf1mtdan3drynj3qmhhczhlrwwrundysg5gavdawmjpyuzzvjzhekjjowlvtxprvux0k3nkqxvjekjfmxbcnznhqvvhsuhhmitouznxbgr6mwparxi1nefmdglcrt19&i=5twu765jrpk1m86a&h=e$rstxag3xx1q=&enckey=eubgygf54wbhrhtocnecbzoczdexhwm09nqpwiv9zuyuu1sjwkb+aln0nhnnyyrtuxajw7ebasnjk7zwp1unslyipnrz0dtgxjcv99wtko4p1ln8inkx3kfdsvejdzn45vnznmzx6ohmeqphzcacoahfa1r/twwszbfxses51us=
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://103.176.111.176/cgi-bin/p.cgi?r=20&i=15tcye420v0z1rfh
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1fpd25sbvfnzdkxelqzqvpfr3fjk09uzxvtutrwyknrsutvbkd5beovqkxyac9yvvllc0v4zevbsutanfv2uk9uoefranz3zkjhbevpcvnsvtjisnfzsdvrvgrksnfzde9ztfp5zmzpsk8xzec2skvleljmm1l2ywvku2zbvmlpl3rmvldjdfmrm3k4v3hpovgytfhxsetuofpvsffxvjrmazvkwxjnmc81n2dovfrycnlecmdlzk1jrtjiquorndjkwlayq2exzgthdgmzeudem3lqrwpzoudlsu4rtzdeqnirvtrjsnq3udrxdzlswlqwc0pcmws5sendew1mdwtzothoszi0mdy1udjtqxnknfn3bjjlqmvqanrmwfj3nkkxrezytghxejl3k05xsuh6dfrbadb3wtfyohlyejmydmzmrs9vl1v5a09hsjmyeg5acnzkzxlswmvkzhben3l2a2kvugl6rgnpzkfqvfo1rw1yq1i4sghrnvp3wghmslz3nwdnufjldxltb3nfmvkymytfexj3ek1tt21cd0poou9xywl1cg01dlnxsstys1fam0uvdy9lu3dyntjywulvtmptzljib2npznfxevppzdnmeve2ahlqvwzunitzukfsymlsatjgrgi5ewewas8zv2q0ug5pvwpumvpwrwzvsk1itgtqblhpwvd2m0d1emw5wfrhbk1vb29lckhmq1lwbk5zbz19&i=15tcye420v0z1rfh&h=e$rsraqno8goy=&enckey=u3nwlhxpyzpvczybyldaagdfw9ybgzio5ki4lnf69fqg06o2tznpyn9t2b0q97vxra6y+7kvtesufs4ablrild1ed5ytjh54e64b0p4zbazyexwqjapxl1rd9paj7ti2jcxwde7k+q6rv7akxwnupm5qicultsxfaonzpbphflu=
http://103.176.111.176/cgi-bin/p.cgi?r=30&i=u225z9b826e2bnbo
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1mzy0jnk2pbsmhqemdochjmeuw5vm5kwglrywk0wjzsbthkdjh5vxrsrnl4sdjgrwt0tnjnbwk0awzlsulmuxjocm93bzdzv3yrttqzvetkykt5bm9frfnty2ncyktjredsnjhxa1hxmk1wcwtpmzzknvbpb3hgvlv3tunvslfdouruzgiwyu1wmugyvvfwcvr5dxrbos8zvflec0rjm0fvk0orvtvmvzhjaznqmfpdrjvhwwhtb3porepqrgfiy1rnnkpznljhetnymlgxt3dqcflpeuq4q1lpoha5n0jnc2kralezajl0n1zrtdrzwitkoge5wgpyzu94mmfiwm54uy9wsnlsblfnrtjgsnbuzflvnthqtfm4vk1ucmfkymk0exnruhzyevzttkjicljkk0z5suxkn0tju1ivmvkywjrmslgyem9bmxhxwlpceffttytjvk5mbufvazgvs2vil0zhukppvhyvzjf6yu12ckxdetcybuljrgxiumjcue92b2xoqu01dwoyt0g3quv3cndoyxlcrudxbg8vqjzpntdwvxhnckrezvm1v0t3l1hyaldpwtj1nm52buo5v2pzajzru2prttv4cm1idkzvdxrdcuo2zjhxaktwrwwvse5nn2xuy1i5q1prd0pqmgdrznnjrvbkmhpkatvhm2h1uzvevuxtmwplz000qxqyumfwb2dmwstgmm8vdepweld4vgl3dz19&i=u225z9b826e2bnbo&h=e$rstpgbtk1km=&enckey=eojle+pdlvbtah24zjxy1de8vn5x2fp5axmpvg4s+hvgllfdhcpzyvly9tupke9tuvrh7pgn1ftlogxnok69hevuxw9nacxbp7i7/gjc+2rf1v3ybreqw92mdefmhcmwtjrz0sy9tfcq+zft3k9vrrqzxorqn0shwkh07ywqcdw=
http://103.176.111.176/cgi-bin/p.cgi?r=25&i=npd72lnk0315246d
http://103.176.111.176/cgi-bin/p.cgi?add=aw5mbyb7rsrsu1e1qukveenymdv0wlz1dss3bdj3svj2dhpfnzl5ctvqauh5uklwbnpvyxq4cnnkzvjlb0j6n0vxl0zyd21pnhazszrrvdvyv0zjsxfiswixqnlwznlbt05qbxlzwlpdk0vwew5lrlj6agpddfftuwjpqwlumk1vtmzjamxavfjbnkryretby0prcerztvpenuddb21zuwduquruduplvlrscmnpcm1vakk1anzjnfnfnta4zulhwturnec4mgwyexn0u1zsn0jnngtlnff2uulvuznqznjavfhreitan1pvm04zmhzkumh0b0zplzjkbjbaqvpsngw2ym85bxv5k1m3vkewrejkl0jgdxbaeghqq3hzotblvkxkwjl0kzf0smwrmhm0szg3anv5y0x4rkhuetb4zwfwzss3eujqmdkwzedqbdjlmjjjbezfehdlrhfreldot2wxmlc5rzz0eu9psznpsnfqbtdicze3vk1ptjvwzjjobuhtddvjtdvvmuzxnjy1empzqmtnyxe0zezkts9fyvryqvnsnknvngnhymtcumv2rtl5m3bgbwhzcvfirlrkcfrpohy1ckk0d1i3qmltadarmehgtwmyofb1cgxerjfwnepvejjiuxlzvy9wn3fwr1dmyxp0mxhprkdqrthnvhfta2fotlbds3zrofrem241d1rhwjfrqzditxndwffltwjlbfvlnws1zld4dvlhqt19&i=npd72lnk0315246d&h=e$rsrbaiyrupw=&enckey=g+i7b9qxrtck/6rutvywxhjpkvburmqchxmbio0dvvk2hkm4z1xzcoik9mqsr6gey2wgvqsztrq3gqthgfty7pmmuai4qx6odude5pq2cq+/hsoyps5ehdyw/u37fh9jr9w8stvvatvbh9ffsvieyhozg2inheiau9unlqsopbe=
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 1128
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 2922
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 10390
comments 0

What is Prometei Botnet?

The Prometei botnet represents one of the most persistent and evolving cryptocurrency mining threats in the cybersecurity landscape. There is evidence that it has been active since 2016, though it was described in 2020.

It is an advanced, multi-component malware system designed to mine cryptocurrency while staying under the radar. Written in multiple programming languages (including Delphi and PowerShell), it supports Windows and Linux platforms and is capable of self-propagation, data exfiltration, and command-and-control (C2) communications.

Its modular architecture allows attackers to dynamically deploy components like credential stealers, backdoors, and lateral movement tools based on the target environment. While its primary goal is cryptojacking, its deep penetration into systems makes it a gateway for broader cyber espionage or sabotage.

The botnet employs domain generation algorithms (DGA) for command and control communications, making it difficult to disrupt its operations through traditional domain blocking methods.

Recent analysis indicates that Prometei has experienced a significant resurgence since March 2025, with updated variants showing enhanced capabilities and more sophisticated anti-analysis features. The malware demonstrates continuous development, with threat actors regularly updating its modules and incorporating new exploitation techniques to maintain effectiveness against modern security measures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Prometei Malware Victimology

Prometei’s victimology is opportunistic rather than highly targeted. It affects a wide range of industries, including finance, insurance, retail, manufacturing, utilities, travel, and construction.

It has been detected across the United States, the United Kingdom, Europe, South America, and East Asia. The botnet exploits unpatched systems, poorly configured servers, and devices with weak security, such as outdated Microsoft Exchange servers or IoT devices with default credentials.

Prometei has infected systems in over 90 countries, with particularly high concentrations observed in Brazil, Indonesia, and Turkey. Recent campaigns have shown over 10,000 systems compromised since November 2022.

What Prometei Botnet Can Do to User Device

Once installed on an endpoint device, Prometei can perform several malicious activities:

  • Cryptocurrency Mining: It hijacks computing resources to mine Monero, often causing significant performance degradation.
  • Credential Theft: It employs modules (e.g. Mimikatz) to harvest login credentials, sometimes using the WDigest protocol to store passwords in plaintext.
  • Data Theft: It can extract sensitive system information, including processor details, OS data, and network configurations.
  • Lateral Movement: It spreads within networks using protocols like RDP, SSH, and SMB.
  • Backdoor Installation: Newer versions include backdoors for persistent access and additional payload deployment.
  • Web Shell Deployment: It can install PHP-based web shells via a bundled Apache web server to execute remote commands.
  • Additional payload download.

How Prometei Malware Threatens Businesses and Organizations

For businesses and organizations, Prometei presents multifaceted threats that extend far beyond cryptocurrency mining. The malware's ability to steal credentials and move laterally through networks means that a single infected system can potentially compromise an entire organizational infrastructure.

The cryptojacking component results in significant financial losses through increased electricity costs, reduced productivity due to system performance degradation, and potential hardware damage requiring replacement. More critically, the backdoor capabilities provide persistent access that can be leveraged for more damaging attacks, including data exfiltration, deployment of additional malware, or ransomware attacks.

The malware's credential harvesting capabilities can result in violations of data protection regulations.

How Does Prometei Botnet Get in the System and Spread?

Similar to other botnets like Mirai and Gafgyt Prometei infects systems through:

  • Exploiting Vulnerabilities: It targets unpatched software, notably Microsoft Exchange Server flaws like ProxyLogon (associated with HAFNIUM attacks).
  • Brute-Force Attacks: It attempts to crack weak administrator passwords via RDP, SSH, or SMB.
  • Phishing Emails: Malicious attachments or links deliver the initial payload.
  • Drive-by Downloads: Compromised websites or fake software updates install the malware.

Once inside a system, it uses spreader modules to propagate across networks, scanning for additional vulnerable endpoints. Its worm-like capabilities enable rapid expansion within poorly secured environments.

How Does Prometei Botnet Function?

Prometei operates through a modular framework, with each component handling specific tasks:

  • Main Module: Executes initial infection and retrieves additional payloads.
  • Spreader Modules: Facilitate lateral movement via RDP, SSH, and SMB.
  • Cryptomining Module: Mines Monero using the infected device’s resources.
  • C2 Communication: Uses a Tor-based C2 server or DGA-generated domains to receive commands and exfiltrate data.
  • Persistence Mechanisms: Creates services, scheduled tasks, or cron jobs to ensure re-infection after system reboots.
  • Web Shell: Deploys a PHP-based web shell for remote command execution. Its self-updating feature and DGA enhance its resilience against takedown efforts.

The botnet utilizes domain generation algorithms to maintain communication with command and control servers, generating new domains dynamically to evade detection and blocking efforts. This technique ensures that even if security teams identify and block known malicious domains, the botnet can continue operating through newly generated communication channels.

Prometei's self-updating capabilities allow it to download and install new modules or updates automatically, ensuring that infected systems remain current with the latest malware variants. This feature contributes to the botnet's longevity and helps it adapt to changing security landscapes and defensive measures.

Prometei Botnet Typical Attack Chain

ANY.RUN’s Interactive Sandbox has seen a variety of Prometei malware samples analyzed by its global community of 500,000 users. Let’s explore one to see how the botnet infiltrates the system.

View analysis

Prometei malware analysis in the Sandbox Prometei Botnet sample detonated in the Sandbox

Prometei starts by making sure there is no older copy of itself on the machine. It searches the running processes for the names uplugplay and upnpsetup with the pgrep command. If it finds either name, it immediately stops those processes with killall5 and pidof. This step clears the way so only the newest version of the malware can run.

When the system is clean, Prometei creates a small file called /etc/CommId. Inside this file it writes a random twelve-character code; in the sample run the code was CPGP332GT4P7AH6F.

Prometei generates code to identify device Prometei generates a code to identify the infected endpoint

Right after that, the malware sends the code to its command-and-control server through an unencrypted HTTP request (http://152[.]36[.]128[.]18/cgi-bin/p.cgi?r=26&i=CPGP332GT4P7AH6F). The attackers use this code to recognize and track the infected computer.

Prometei sends code to c2c server The code gets sent to C2C server

Next, the malware makes sure it will survive a reboot. It drops a new systemd service file called uplugplay.service in the folder /lib/systemd/system/. The service is listed under the friendly name UPlugPlay and is set to run the program /usr/sbin/uplugplay.

Prometei persistence mechanism Part of Prometei persistence mechanism

Prometei copies its own binary into that location, deletes the original dropper, and then runs two shell commands: systemctl enables uplugplay.service and systemctl starts uplugplay.service. These commands turn the service on right away and guarantee it will start automatically whenever the operating system boots.

After installation, the program becomes quiet. It checks whether it was launched with an extra parameter, so it can switch from the installer role to its normal botnet duties. The parameter it expects later is “Dcomsvc”, which would be used like this: /usr/sbin/uplugplay -Dcomsvc. Once everything is in place, Prometei waits in the background for more instructions from its command-and-control server, ready to carry out whatever tasks the attackers send next.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Gathering Threat Intelligence on Prometei malware

Threat intelligence plays a crucial role in defending against Prometei by providing actionable information about the malware's tactics, techniques, and procedures.

Behavioral intelligence describing Prometei's operational patterns helps security teams develop effective detection rules and monitoring strategies. Understanding the malware's lateral movement techniques and persistence mechanisms enables more comprehensive threat hunting activities.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"prometei"

Prometei malware samples found via TI Lookup Prometei Botnet samples recently analyzed in ANY.RUN's Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Prometei Botnet is more than just another cryptominer — it’s a modular, persistent, and evasive malware that undermines enterprise security while silently monetizing your infrastructure. With its stealth tactics, lateral movement, and built-in credential theft, it opens doors to deeper compromise. Preventing Prometei requires rigorous patching, strong authentication, and proactive threat intelligence. By understanding its tactics and staying informed with real-time threat data, organizations can turn the tide against this parasitic threat.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

DarkTortilla screenshot
DarkTortilla
darktortilla
DarkTortilla is a crypter used by attackers to spread harmful software. It can modify system files to stay hidden and active. DarkTortilla is a multi-stage crypter that relies on several components to operate. It is often distributed through phishing sites that look like real services.
Read More
SmartLoader screenshot
SmartLoader
smartloader
SmartLoader is a Windows malware loader that uses multi-stage execution to deliver secondary payloads. It supports system discovery, screenshot capture, persistence through scheduled tasks, C2 communication, and anti-analysis techniques.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More