logo

Prometei campaign (Campaign)

ID: 354a530f-bab7-5630-91b3-51f697d5e1ad

STIX ID: report--354a530f-bab7-5630-91b3-51f697d5e1ad

Feed Name: Wiz Cloud Threat Landscape

Threat Score
72/100

Date Published: 2024-10-23

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Trend Micro identified the Prometei botnet attempting to infiltrate corporate networks via brute-force password attacks and exploitation of RDP/SMB; the modular malware deploys PowerShell-based persistence, uses a domain generation algorithm for C2, and employs encrypted and Base64-obfuscated payloads to evade detection, focusing on cryptocurrency mining and credential theft and attributed to Russian-speaking operators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.