Prometei is a modular cryptomining botnet first discovered by Cisco Talos in July 2020, targeting Windows systems globally to mine the Monero cryptocurrency. Operated by an unidentified Russian-speaking threat actor, the malware combines worm-like propagation with credential theft and is classified as a hybrid botnet and cryptocurrency miner.
Prometei spreads using multiple propagation methods, including exploitation of the SMBv1 vulnerability CVE-2017-0144 (EternalBlue), brute-forcing RDP and SSH credentials, and leveraging SMB password guessing. It also exploits the SQL injection vulnerability CVE-2020-5902 in F5 BIG-IP devices to gain initial access. Once inside a network, it establishes persistence via scheduled tasks and Windows services, and uses a custom peer-to-peer (P2P) command-and-control (C2) infrastructure blended with HTTP-based C2 servers. The botnet employs evasion techniques such as disabling Windows Defender, deleting competing miners, and using process hollowing to hide its mining payload. It also spreads through the SMB shares by copying itself as a renamed executable, and can laterally move via WMI and PowerShell scripts.
Prometei was first described by Cisco Talos in a July 2020 report, noting its rapid expansion across healthcare, finance, and manufacturing sectors. A second major campaign was documented in March 2021 by Talos, revealing updated modules and improved P2P communication. No law enforcement actions or arrests have been publicly reported, but the malware continues to be actively monitored by security vendors including Microsoft (tracked as 'Prometei') and Trend Micro. The botnet has exploited CVE-2017-0144 and CVE-2020-5902 in observed attacks.
Known IOCs include installer and payload file hashes (SHA256: 0a5f5e8a... and others published by Talos), network traffic to specific C2 domains such as 'prometei[.]xyz', and User-Agent strings like 'Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36' used during HTTP callbacks. Registry keys under 'HKLMSoftwareMicrosoftWindowsCurrentVersionRun' for persistence, and mutex names like 'PrometeiMutex' are also common indicators.
Prometei primarily causes financial damage through unauthorized cryptocurrency mining, consuming CPU and GPU resources and increasing electricity costs for victims. It also exfiltrates system information and credentials, posing a secondary risk of data breach and lateral movement into sensitive networks. Affected sectors include healthcare, finance, manufacturing, and critical infrastructure, with incidents reported across Europe, North America, and Asia.
Mitigation strategies include patching SMBv1 (disable via group policy), applying updates for CVE-2020-5902, enforcing strong password policies for RDP and SSH, and deploying endpoint detection and response (EDR) tools with rules for mining behavior and process hollowing. Cisco Talos and Microsoft provide YARA rules and behavioral detections in their security products.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.