216.73.217.22

Resurgence of the Prometei Botnet

· Published 20/06/2025 13:10 · Modified 23/06/2025 23:06

Export JSON

Essential information

Published
20/06/2025 13:10
Modified
23/06/2025 23:06
Tags
2025-06-20 backdoor botnet credential-theft cryptominer dga linux prometei
Related entities
11 observables, 1 intrusion sets (apt)

Description

Unit 42 researchers identified a new wave of attacks in March 2025. The malware, which includes and Windows variants, allows remote control of compromised systems for cryptocurrency mining and credential theft. is actively developed, incorporating new modules and methods, including a for various malicious activities. It uses a domain generation algorithm for C2 infrastructure and self-updating features for evasion. The article analyzes versions three and four of the variant, highlighting differences from version two. 's modular architecture makes it highly adaptable, with components for brute-forcing credentials, exploiting vulnerabilities, mining cryptocurrency, stealing data, and C2 communication. The 's primary goal is Monero mining, but it also has secondary capabilities like credential theft and deploying additional malware payloads.

External references