TF-MAL-elf.prometei
📛 Threat Title
Malware family: Prometei
Description
ThreatFox malware family `elf.prometei`. Printable name: Prometei.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.prometei
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.prometei
IOC database
- Type
- domain
- Value
elf.prometei- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.prometei
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.prometei
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (8)
-
web:any.run
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
-
web:blog.netmanageit.com
The malware , which includes Linux and Windows variants, allows remote control of compromised systems for cryptocurrency mining and credential theft. Prometei is actively developed, incorporating new modules and methods, including a backdoor for various malicious activities.
-
web:cybersecuritynews.com
The Prometei botnet represents a dual-threat malware family encompassing both Linux and Windows variants, designed primarily to hijack computational resources for Monero cryptocurrency mining while simultaneously stealing credentials from compromised systems.
-
web:redteamnews.com
The Prometei botnet has evolved into a sophisticated threat since its emergence in 2016, now leveraging Microsoft Exchange vulnerabilities and advanced evasion techniques to conduct cryptocurrency mining at scale. Trend Micro's Managed Extended Detection and Response (MXDR) team recently uncovered new details about its modular architecture, command-and-control infrastructure, and operational ...
-
web:stairwell.com
Malware and botnet Prometei continues to evolve. The Stairwell Threat Research team uncovers 53 variants of Prometei and shares three new YARA rules to support detection efforts. How Prometei Re-appeared On June 20th, researchers at Palo Alto Networks released a report on the modular cryptocurrency botnet and malware , both by the name Prometei . Prometei was […]
-
web:unit42.paloaltonetworks.com
In March 2025, Unit 42 researchers identified a wave of Prometei attacks. Prometei refers to both the botnet and the malware family used to operate it. This malware family , which includes both Linux and Windows variants, allows attackers to remotely control compromised systems for cryptocurrency mining (particularly Monero) and credential theft.
-
web:www.securityweek.com
An updated variant of the Prometei malware is making the rounds, and activity associated with the botnet has surged over the past months, Palo Alto Networks reports. A modular botnet initially discovered in July 2020, Prometei targets both Windows and Linux systems for infection, primarily for cryptocurrency mining and credential exfiltration.
-
web:www.trendmicro.com
The Prometei botnet, reportedly dating back to as far back as 2016 and updated to version 3 in late 2022, is a modular malware family used primarily for cryptocurrency mining (especially Monero) and credential theft. By early 2023, it had compromised over 10,000 systems globally, with significant activity in Brazil, Indonesia, and Turkey.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.