logo

Resurgence of the Prometei Botnet

ID: b3e01c8a-b773-5b74-8fdf-95f29a796cd9

STIX ID: report--b3e01c8a-b773-5b74-8fdf-95f29a796cd9

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-06-20

Date Updated: 2026-04-28

Author: Lee Wei Yeong and Pranay Kumar Chhaparwal

...
...

Unit 42 researchers describe a March 2025 resurgence of the Prometei botnet’s Linux variants, detailing how the malware is distributed via HTTP, packed with UPX combined with a custom JSON configuration trailer that thwarts standard unpackers, and how it performs system reconnaissance, Monero mining, credential theft, lateral movement, and C2 communications (including a DGA and self-updating capabilities). The report provides static analysis differences between versions, unpacking guidance, a timeline of observed samples, multiple SHA-256 hashes for samples, distribution and C2 URLs, and recommended detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.