Resurgence of the Prometei Botnet
ID: b3e01c8a-b773-5b74-8fdf-95f29a796cd9
STIX ID: report--b3e01c8a-b773-5b74-8fdf-95f29a796cd9
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-06-20
Date Updated: 2026-04-28
Author: Lee Wei Yeong and Pranay Kumar Chhaparwal
Unit 42 researchers describe a March 2025 resurgence of the Prometei botnet’s Linux variants, detailing how the malware is distributed via HTTP, packed with UPX combined with a custom JSON configuration trailer that thwarts standard unpackers, and how it performs system reconnaissance, Monero mining, credential theft, lateral movement, and C2 communications (including a DGA and self-updating capabilities). The report provides static analysis differences between versions, unpacking guidance, a timeline of observed samples, multiple SHA-256 hashes for samples, distribution and C2 URLs, and recommended detections and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
