s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-php.prometheus_backdoor

📛 Threat Title

Malware family: Prometheus Backdoor

Category: Prometheus Backdoor First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `php.prometheus_backdoor`. Printable name: Prometheus Backdoor.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cybernews.com

    A new BRICKSTORM malware advisory released by CISA on Thursday aims to help organizations defend their systems against the backdoor APT - a stealthy, evasive cyberespionage threat already in use by PRC-backed nation-state attackers.

  • web:malpedia.caad.fkie.fraunhofer.de

    Backdoor written in php 2022-01-19 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team Kraken the Code on Prometheus Prometheus Backdoor BlackMatter Cerber Cobalt Strike DCRat Ficker Stealer QakBot REvil Ryuk 2021-08-05 ⋅ Group-IB ⋅ Nikita Rostovcev, Viktor Okorokov Prometheus TDS The key to success for Campo Loader, Hancitor, IcedID, and QBot Prometheus Backdoor Buer ...

  • web:media.defense.gov

    Malware Summary BRICKSTORM is a custom Executable and Linkable Format (ELF) Go- or Rust-based backdoor (eight originally analyzed samples are Go-based, and two of the three new samples in the Dec. 19, 2025, update are Rust-based).

  • web:prometheus.io

    Prometheus is a sophisticated system with many components and many integrations with other systems. It can be deployed in a variety of trusted and untrusted environments. This page describes the general security assumptions of Prometheus and the attack vectors that some configurations may enable.

  • web:www.cisa.gov

    Malware Summary BRICKSTORM is a custom Executable and Linkable Format (ELF) Go-or Rust-based backdoor (eight originally analyzed samples are Go-based, and two of the three new samples in the Dec. 19, 2025, update are Rust-based).

  • web:www.cyber.gc.ca

    This joint report warns that People's Republic of China (PRC) state-sponsored threat actors are using Brickstorm malware for long-term persistence on victims' systems.

  • web:www.malwarebytes.com

    Backdoor .Remcos is Malwarebytes' detection name for a family of Backdoor Trojans that allow remote access and control over the affected system.

  • web:www.netsecurity.com

    On December 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and the Canadian Centre for Cyber Security (Cyber Centre), released Malware Analysis Report AR25-338A detailing a significant cyber threat: BRICKSTORM, a highly advanced backdoor attributed to state-sponsored actors from the People's Republic of China ...

  • web:www.nsa.gov

    FORT MEADE, Md. - The National Security Agency (NSA) is joining the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure ...

  • web:www.sentinelone.com

    Prometheus ransomware claims ties to REvil, using fear and data leaks. Understand its intimidation tactics and learn how to protect your files.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.