Prometei Botnet Activity Spikes

An updated version of the Prometei malware continues to evolve, focusing on cryptocurrency mining, credential theft, and evasion techniques. Its activity surge highlights its ongoing development and active use by threat actors targeting Linux and Windows systems. #Prometei #DGA

Keypoints

  • Prometei is a modular botnet targeting Windows and Linux for cryptocurrency mining and credential theft.
  • The latest version includes a backdoor, self-updating features, and uses a domain generation algorithm for C&C communication.
  • It employs techniques like brute-force password attacks, vulnerability exploitation, and lateral movement.
  • The malware creates persistence through services and cron jobs, and decompresses itself in memory during runtime.
  • Its core operations are driven by financial motives, focusing primarily on Monero mining with secondary credential theft capabilities.

Read More: https://www.securityweek.com/prometei-botnet-activity-spikes/