logo

Prometei Botnet Attacking Windows Server to Gain Remote Access and Deploy Malware

ID: 02f31490-58de-5323-b540-2075d8cb83d9

STIX ID: report--02f31490-58de-5323-b540-2075d8cb83d9

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-02-11

Date Updated: 2026-04-21

Author: Abinaya

...
...

Prometei is a Russian-linked, multi-functional botnet active since 2016 that compromises Windows Server systems via weak/default RDP credentials, deploys as a persistent Windows service (UPlugPlay / C:\Windows\sqhost.exe), and performs cryptocurrency mining, credential theft (Mimikatz variants), lateral movement, and anonymous C2 communications over TOR and the clear web. The malware uses multiple encryption layers (RC4, LZNT1, RSA-1024), rolling XOR key ciphers, and evasive techniques (Defender exclusions, firewall exceptions, sandbox evasion) and supports modular updates (netdefender, rdpcIip, windrlver, TOR proxies) to ensure long-term, exclusive control of compromised hosts; YARA rules and detection guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.