s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.prometei

📛 Threat Title

Malware family: Prometei

Category: Prometei First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.prometei`. Printable name: Prometei.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.prometei VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.prometei

IOC database

Type
domain
Value
elf.prometei
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.prometei

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.prometei

References (1)

Remediations (8)

  • web:any.run

    Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.

  • web:blog.netmanageit.com

    The malware , which includes Linux and Windows variants, allows remote control of compromised systems for cryptocurrency mining and credential theft. Prometei is actively developed, incorporating new modules and methods, including a backdoor for various malicious activities.

  • web:cybersecuritynews.com

    The Prometei botnet represents a dual-threat malware family encompassing both Linux and Windows variants, designed primarily to hijack computational resources for Monero cryptocurrency mining while simultaneously stealing credentials from compromised systems.

  • web:redteamnews.com

    The Prometei botnet has evolved into a sophisticated threat since its emergence in 2016, now leveraging Microsoft Exchange vulnerabilities and advanced evasion techniques to conduct cryptocurrency mining at scale. Trend Micro's Managed Extended Detection and Response (MXDR) team recently uncovered new details about its modular architecture, command-and-control infrastructure, and operational ...

  • web:stairwell.com

    Malware and botnet Prometei continues to evolve. The Stairwell Threat Research team uncovers 53 variants of Prometei and shares three new YARA rules to support detection efforts. How Prometei Re-appeared On June 20th, researchers at Palo Alto Networks released a report on the modular cryptocurrency botnet and malware , both by the name Prometei . Prometei was […]

  • web:unit42.paloaltonetworks.com

    In March 2025, Unit 42 researchers identified a wave of Prometei attacks. Prometei refers to both the botnet and the malware family used to operate it. This malware family , which includes both Linux and Windows variants, allows attackers to remotely control compromised systems for cryptocurrency mining (particularly Monero) and credential theft.

  • web:www.securityweek.com

    An updated variant of the Prometei malware is making the rounds, and activity associated with the botnet has surged over the past months, Palo Alto Networks reports. A modular botnet initially discovered in July 2020, Prometei targets both Windows and Linux systems for infection, primarily for cryptocurrency mining and credential exfiltration.

  • web:www.trendmicro.com

    The Prometei botnet, reportedly dating back to as far back as 2016 and updated to version 3 in late 2022, is a modular malware family used primarily for cryptocurrency mining (especially Monero) and credential theft. By early 2023, it had compromised over 10,000 systems globally, with significant activity in Brazil, Indonesia, and Turkey.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.