Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Prometei

114
Global rank
69 infographic chevron month
Month rank
103 infographic chevron week
Week rank
0
IOCs

Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

Botnet
Type
Unknown
Origin
1 March, 2016
First seen
11 September, 2026
Last seen

How to analyze Prometei with ANY.RUN

Type
Unknown
Origin
1 March, 2016
First seen
11 September, 2026
Last seen

IOCs

IP addresses
91.189.91.58
31.56.209.100
185.125.190.56
185.125.190.57
91.189.91.60
91.189.91.64
192.178.183.136
48.209.138.168
23.0.174.97
142.251.150.119
20.190.159.68
23.200.214.115
142.251.127.84
74.178.240.61
23.11.41.157
142.251.20.95
178.105.255.79
2.19.252.163
172.217.118.4
57.153.246.3
Hashes
2bc860efee229662a3c55dcf6e50d6142b3eec99c606faa1210f24541cad12f5
f845be2b7ded6f3e2bbcf2f80c485ae1f23bfad99e534ad4e554f19cbe6342a6
c655d3d4e374fad38313ec4262207b2d7d68a870238f203ef3c33f85e66c8e32
889515367cfc5ba8f8eb99d215ab3ccc65d4ad61d89247264b4019d7cf6cb09c
a8eac752e2d37d7afcc7a48f0c09d8ab2bb737422037465fb43845913d3f58c4
dc43fdfbb5f7e8ecc80353dcd85889c0c08483c99acbce35b3ed8f399c936920
9dbbc9b5d7793425968e42e995226c5f9fe32e502a0a694320a5e838d57c8836
08caefcaed31eb1fe6f0271019897483d2030011d3ac290eabefb2322947d41c
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
c52c62a7c50daf7d3f73ec16977cd4b0ea401710807d5dbe3850941dd1b73a70
d571ef33b0e707571f10bb37b99a607d6f43afe33f53d15b4395b16ef3fda665
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
8223a912160354e05735522fdb339dc59b353ad5d1e4f4cfa94898dc348e748f
8c5fa4b29519d17593e923bc6a9a284df7a6d07fac42f897110b8fb2e0baeef5
af0edb67c2219b803c3eb6c1dee6f2d41a3fe00468a9da8be8ef5056d701abf3
97a4755fe9e653a08969f1933e3db19c712078b227bd5aa6799093abc5a0edc3
c2784e33158a807135850f7125a7eaabe472b3cfc7afb82c74f02da69ea250fe
Domains
p1.feefreepool.net
connectivity-check.ubuntu.com
google.com
clients1.google.com
sb-ssl.google.com
activation-v2.sls.microsoft.com
update.googleapis.com
slscr.update.microsoft.com
chromewebstore.googleapis.com
safebrowsing.googleapis.com
edgedl.me.gvt1.com
clients2.google.com
client.wns.windows.com
nexusrules.officeapps.live.com
go.microsoft.com
www.bing.com
crl.microsoft.com
settings-win.data.microsoft.com
optimizationguide-pa.googleapis.com
login.live.com
URLs
http://connectivity-check.ubuntu.com/
http://clients2.google.com/time/1/current?cup2key=8:74wzndzrqsifzzd9wojqpr6armyrmgqz5gczljbbie0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://178.105.255.79/dota3.tar.gz
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://update.googleapis.com/service/update2/json?cup2key=14:s5imqvd5andr72psxo3xnfq8o3vzlrcoodzmo7jbfxa&cup2hreq=1dcc989871a64e5e085f2df5d088972a6629d7ec35efb7f052e9f607541d32c6
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://optimizationguide-pa.googleapis.com/v1:getmodels?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://optimizationguide-pa.googleapis.com/downloads?name=1679317318&target=optimization_target_language_detection
https://optimizationguide-pa.googleapis.com/downloads?name=1753110098&target=optimization_target_notification_permission_predictions
https://optimizationguide-pa.googleapis.com/downloads?name=1696267841&target=optimization_target_omnibox_url_scoring
https://optimizationguide-pa.googleapis.com/downloads?name=1753110074&target=optimization_target_geolocation_permission_predictions
https://optimizationguide-pa.googleapis.com/downloads?name=1781017313&target=optimization_target_client_side_phishing
Last Seen at

Recent blog posts

post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 1666
comments 0
post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 3504
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 6612
comments 0

What is Prometei Botnet?

The Prometei botnet represents one of the most persistent and evolving cryptocurrency mining threats in the cybersecurity landscape. There is evidence that it has been active since 2016, though it was described in 2020.

It is an advanced, multi-component malware system designed to mine cryptocurrency while staying under the radar. Written in multiple programming languages (including Delphi and PowerShell), it supports Windows and Linux platforms and is capable of self-propagation, data exfiltration, and command-and-control (C2) communications.

Its modular architecture allows attackers to dynamically deploy components like credential stealers, backdoors, and lateral movement tools based on the target environment. While its primary goal is cryptojacking, its deep penetration into systems makes it a gateway for broader cyber espionage or sabotage.

The botnet employs domain generation algorithms (DGA) for command and control communications, making it difficult to disrupt its operations through traditional domain blocking methods.

Recent analysis indicates that Prometei has experienced a significant resurgence since March 2025, with updated variants showing enhanced capabilities and more sophisticated anti-analysis features. The malware demonstrates continuous development, with threat actors regularly updating its modules and incorporating new exploitation techniques to maintain effectiveness against modern security measures.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Prometei Malware Victimology

Prometei’s victimology is opportunistic rather than highly targeted. It affects a wide range of industries, including finance, insurance, retail, manufacturing, utilities, travel, and construction.

It has been detected across the United States, the United Kingdom, Europe, South America, and East Asia. The botnet exploits unpatched systems, poorly configured servers, and devices with weak security, such as outdated Microsoft Exchange servers or IoT devices with default credentials.

Prometei has infected systems in over 90 countries, with particularly high concentrations observed in Brazil, Indonesia, and Turkey. Recent campaigns have shown over 10,000 systems compromised since November 2022.

What Prometei Botnet Can Do to User Device

Once installed on an endpoint device, Prometei can perform several malicious activities:

  • Cryptocurrency Mining: It hijacks computing resources to mine Monero, often causing significant performance degradation.
  • Credential Theft: It employs modules (e.g. Mimikatz) to harvest login credentials, sometimes using the WDigest protocol to store passwords in plaintext.
  • Data Theft: It can extract sensitive system information, including processor details, OS data, and network configurations.
  • Lateral Movement: It spreads within networks using protocols like RDP, SSH, and SMB.
  • Backdoor Installation: Newer versions include backdoors for persistent access and additional payload deployment.
  • Web Shell Deployment: It can install PHP-based web shells via a bundled Apache web server to execute remote commands.
  • Additional payload download.

How Prometei Malware Threatens Businesses and Organizations

For businesses and organizations, Prometei presents multifaceted threats that extend far beyond cryptocurrency mining. The malware's ability to steal credentials and move laterally through networks means that a single infected system can potentially compromise an entire organizational infrastructure.

The cryptojacking component results in significant financial losses through increased electricity costs, reduced productivity due to system performance degradation, and potential hardware damage requiring replacement. More critically, the backdoor capabilities provide persistent access that can be leveraged for more damaging attacks, including data exfiltration, deployment of additional malware, or ransomware attacks.

The malware's credential harvesting capabilities can result in violations of data protection regulations.

How Does Prometei Botnet Get in the System and Spread?

Similar to other botnets like Mirai and Gafgyt Prometei infects systems through:

  • Exploiting Vulnerabilities: It targets unpatched software, notably Microsoft Exchange Server flaws like ProxyLogon (associated with HAFNIUM attacks).
  • Brute-Force Attacks: It attempts to crack weak administrator passwords via RDP, SSH, or SMB.
  • Phishing Emails: Malicious attachments or links deliver the initial payload.
  • Drive-by Downloads: Compromised websites or fake software updates install the malware.

Once inside a system, it uses spreader modules to propagate across networks, scanning for additional vulnerable endpoints. Its worm-like capabilities enable rapid expansion within poorly secured environments.

How Does Prometei Botnet Function?

Prometei operates through a modular framework, with each component handling specific tasks:

  • Main Module: Executes initial infection and retrieves additional payloads.
  • Spreader Modules: Facilitate lateral movement via RDP, SSH, and SMB.
  • Cryptomining Module: Mines Monero using the infected device’s resources.
  • C2 Communication: Uses a Tor-based C2 server or DGA-generated domains to receive commands and exfiltrate data.
  • Persistence Mechanisms: Creates services, scheduled tasks, or cron jobs to ensure re-infection after system reboots.
  • Web Shell: Deploys a PHP-based web shell for remote command execution. Its self-updating feature and DGA enhance its resilience against takedown efforts.

The botnet utilizes domain generation algorithms to maintain communication with command and control servers, generating new domains dynamically to evade detection and blocking efforts. This technique ensures that even if security teams identify and block known malicious domains, the botnet can continue operating through newly generated communication channels.

Prometei's self-updating capabilities allow it to download and install new modules or updates automatically, ensuring that infected systems remain current with the latest malware variants. This feature contributes to the botnet's longevity and helps it adapt to changing security landscapes and defensive measures.

Prometei Botnet Typical Attack Chain

ANY.RUN’s Interactive Sandbox has seen a variety of Prometei malware samples analyzed by its global community of 500,000 users. Let’s explore one to see how the botnet infiltrates the system.

View analysis

Prometei malware analysis in the Sandbox Prometei Botnet sample detonated in the Sandbox

Prometei starts by making sure there is no older copy of itself on the machine. It searches the running processes for the names uplugplay and upnpsetup with the pgrep command. If it finds either name, it immediately stops those processes with killall5 and pidof. This step clears the way so only the newest version of the malware can run.

When the system is clean, Prometei creates a small file called /etc/CommId. Inside this file it writes a random twelve-character code; in the sample run the code was CPGP332GT4P7AH6F.

Prometei generates code to identify device Prometei generates a code to identify the infected endpoint

Right after that, the malware sends the code to its command-and-control server through an unencrypted HTTP request (http://152[.]36[.]128[.]18/cgi-bin/p.cgi?r=26&i=CPGP332GT4P7AH6F). The attackers use this code to recognize and track the infected computer.

Prometei sends code to c2c server The code gets sent to C2C server

Next, the malware makes sure it will survive a reboot. It drops a new systemd service file called uplugplay.service in the folder /lib/systemd/system/. The service is listed under the friendly name UPlugPlay and is set to run the program /usr/sbin/uplugplay.

Prometei persistence mechanism Part of Prometei persistence mechanism

Prometei copies its own binary into that location, deletes the original dropper, and then runs two shell commands: systemctl enables uplugplay.service and systemctl starts uplugplay.service. These commands turn the service on right away and guarantee it will start automatically whenever the operating system boots.

After installation, the program becomes quiet. It checks whether it was launched with an extra parameter, so it can switch from the installer role to its normal botnet duties. The parameter it expects later is “Dcomsvc”, which would be used like this: /usr/sbin/uplugplay -Dcomsvc. Once everything is in place, Prometei waits in the background for more instructions from its command-and-control server, ready to carry out whatever tasks the attackers send next.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Gathering Threat Intelligence on Prometei malware

Threat intelligence plays a crucial role in defending against Prometei by providing actionable information about the malware's tactics, techniques, and procedures.

Behavioral intelligence describing Prometei's operational patterns helps security teams develop effective detection rules and monitoring strategies. Understanding the malware's lateral movement techniques and persistence mechanisms enables more comprehensive threat hunting activities.

Start gathering IOCs and behavioral data with the malware name search request to Threat Intelligence Lookup:

threatName:"prometei"

Prometei malware samples found via TI Lookup Prometei Botnet samples recently analyzed in ANY.RUN's Sandbox

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Prometei Botnet is more than just another cryptominer — it’s a modular, persistent, and evasive malware that undermines enterprise security while silently monetizing your infrastructure. With its stealth tactics, lateral movement, and built-in credential theft, it opens doors to deeper compromise. Preventing Prometei requires rigorous patching, strong authentication, and proactive threat intelligence. By understanding its tactics and staying informed with real-time threat data, organizations can turn the tide against this parasitic threat.

Gather fresh actionable threat intelligence via ANY.RUN’s TI Lookup: start with 50 trial requests.

HAVE A LOOK AT

Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Adware screenshot
Adware
adware
Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.
Read More
Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Maze screenshot
Maze
maze ransomware
Maze is ransomware — a malware type that encrypts the victim’s files and restores the data in exchange for a ransom payment. One of the most distinguishable features of Maze is that it is one of the first malware of the kind to publicly release stolen data.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More