Prometei Botnet Attacking Windows Server to Gain Remote Access and Deploy Malware
ID: 02f31490-58de-5323-b540-2075d8cb83d9
STIX ID: report--02f31490-58de-5323-b540-2075d8cb83d9
Feed Name: cybersecurityNews.com
Prometei is a Russian-linked, multi-functional botnet active since 2016 that compromises Windows Server systems via weak/default RDP credentials, deploys as a persistent Windows service (UPlugPlay / C:\Windows\sqhost.exe), and performs cryptocurrency mining, credential theft (Mimikatz variants), lateral movement, and anonymous C2 communications over TOR and the clear web. The malware uses multiple encryption layers (RC4, LZNT1, RSA-1024), rolling XOR key ciphers, and evasive techniques (Defender exclusions, firewall exceptions, sandbox evasion) and supports modular updates (netdefender, rdpcIip, windrlver, TOR proxies) to ensure long-term, exclusive control of compromised hosts; YARA rules and detection guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
