UK Construction Firm Hit by Prometei Botnet Hiding in Windows Server
ID: a938f4fe-bcef-50ba-9140-d156b91969c6
STIX ID: report--a938f4fe-bcef-50ba-9140-d156b91969c6
Feed Name: HackRead
In January 2026 eSentire TRU identified a Prometei botnet infection on a UK construction firm’s Windows server: actors likely gained access via weak RDP credentials, installed persistent components (UPlugPlay, sqhost.exe, zsvc.exe), mined Monero, stole credentials using a Mimikatz variant (miWalk), routed traffic through TOR, used sandbox-evasion decoys, and deployed tools to block other attackers; eSentire released unpacking tools and recommends strong passwords, MFA, and timely patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
