TF-MAL-php.prometheus_backdoor
📛 Threat Title
Malware family: Prometheus Backdoor
Description
ThreatFox malware family `php.prometheus_backdoor`. Printable name: Prometheus Backdoor.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybernews.com
A new BRICKSTORM malware advisory released by CISA on Thursday aims to help organizations defend their systems against the backdoor APT - a stealthy, evasive cyberespionage threat already in use by PRC-backed nation-state attackers.
-
web:malpedia.caad.fkie.fraunhofer.de
Backdoor written in php 2022-01-19 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team Kraken the Code on Prometheus Prometheus Backdoor BlackMatter Cerber Cobalt Strike DCRat Ficker Stealer QakBot REvil Ryuk 2021-08-05 ⋅ Group-IB ⋅ Nikita Rostovcev, Viktor Okorokov Prometheus TDS The key to success for Campo Loader, Hancitor, IcedID, and QBot Prometheus Backdoor Buer ...
-
web:media.defense.gov
Malware Summary BRICKSTORM is a custom Executable and Linkable Format (ELF) Go- or Rust-based backdoor (eight originally analyzed samples are Go-based, and two of the three new samples in the Dec. 19, 2025, update are Rust-based).
-
web:prometheus.io
Prometheus is a sophisticated system with many components and many integrations with other systems. It can be deployed in a variety of trusted and untrusted environments. This page describes the general security assumptions of Prometheus and the attack vectors that some configurations may enable.
-
web:www.cisa.gov
Malware Summary BRICKSTORM is a custom Executable and Linkable Format (ELF) Go-or Rust-based backdoor (eight originally analyzed samples are Go-based, and two of the three new samples in the Dec. 19, 2025, update are Rust-based).
-
web:www.cyber.gc.ca
This joint report warns that People's Republic of China (PRC) state-sponsored threat actors are using Brickstorm malware for long-term persistence on victims' systems.
-
web:www.malwarebytes.com
Backdoor .Remcos is Malwarebytes' detection name for a family of Backdoor Trojans that allow remote access and control over the affected system.
-
web:www.netsecurity.com
On December 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and the Canadian Centre for Cyber Security (Cyber Centre), released Malware Analysis Report AR25-338A detailing a significant cyber threat: BRICKSTORM, a highly advanced backdoor attributed to state-sponsored actors from the People's Republic of China ...
-
web:www.nsa.gov
FORT MEADE, Md. - The National Security Agency (NSA) is joining the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems. BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure ...
-
web:www.sentinelone.com
Prometheus ransomware claims ties to REvil, using fear and data leaks. Understand its intimidation tactics and learn how to protect your files.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.