Threat reportMalwareTL-2026-1490

Prometei Botnet (Linux/Prometei.B) — UPX-Packed Monero-Mining Bot with Cron/systemd Persistence, HTTP/DGA C2, and Tor/I2P Fallback

mediumACTIVE

Prometei Botnet (Linux/Prometei.B) (TL-2026-1490), also tracked as Linux/Prometei.B, is a medium-severity malware campaign, first published 2026-02-20. It has no confirmed attribution, affects Linux Linux servers (x86_64), maps to 29 MITRE ATT&CK techniques (T1003, T1021.001, T1021.002), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1490

Threat ID
TL-2026-1490
Also known as
Linux/Prometei.B
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
unspecified opportunistic internet-facing servers
Target regions
united states of america, brazil, turkey, pakistan, china, mexico, chile, germany, hong kong, indonesia
Detection rules
9
Indicators of compromise
28

Malware and tooling in Prometei Botnet (Linux/Prometei.B)

Malware and tooling: Linux/Prometei.B, Prometei, FreeRDP, Mimikatz (modified), XMRig

How Prometei Botnet (Linux/Prometei.B) works

A February 2025 Linux/Prometei.B botnet sample (SHA-256 cc7ab872ed9c25d4346b4c58c5ef8ea48c2d7b256f20fe2f0912572208df5c1a) was reverse-engineered with Radare2's r2ai extension and Claude 3.5 Sonnet. The UPX-packed ELF x86_64 binary installs as either standard user or root, persists via a cron job and a systemd service named uplugplay, and communicates over HTTP with an appended encrypted-key JSON configuration trailer plus Tor/I2P fallback and DGA-based C2 resilience. Independent March-April 2025 Unit 42 telemetry confirms a broader Prometei resurgence wave targeting Linux servers with credential theft, brute-forcing, and self-updating modules; the family has been active since December 2020 (Linux) / July 2020 (Windows) and mines Monero (XMR) via an embedded XMRig-derived module.

Prometei is a modular, cross-platform (Windows and Linux) botnet first identified in July 2020 (Windows) and December 2020 (Linux), financially motivated and built around Monero (XMR) cryptocurrency mining. This record documents a February 2, 2025 Linux/Prometei.B sample (SHA-256 cc7ab872ed9c25d4346b4c58c5ef8ea48c2d7b256f20fe2f0912572208df5c1a), publicly reverse-engineered by researcher cryptax using Radare2 with the r2ai AI-assisted analysis extension (backed by Claude 3.5 Sonnet via the Anthropic API). The sample is a 64-bit ELF packed with UPX 3.95; standard `upx -d` decompression failed because the malware author appends a custom JSON configuration trailer (fields observed: config, id, enckey, and in newer v3/v4 variants ParentId, ParentHostname, ParentIp, ip) directly after the UPX-compressed payload, which corrupts the UPX footer that unpacking tools rely on and requires the trailer to be manually stripped before standard decompression succeeds. This packing quirk limited the depth of the AI-assisted static analysis in the source writeup (Part One of an ongoing series), leaving several functions and control-flow paths only partially characterized.

Once executed, the dropper copies itself into a persistent location (observed under /usr/sbin as the binary/service name `uplugplay`), and establishes persistence through two redundant mechanisms: a cron job entry and a systemd service unit (also named uplugplay on Linux, mirrored by a Windows service historically named "UPlugPlay" pointing at C:\Windows\svchost.exe in the Windows branch of the family). The installer supports both unprivileged (standard-user) and privileged (root) install paths, broadening the range of initial-access foothold levels it can operationalize. After installation the binary performs systemd bookkeeping (checks service status, reloads systemd unit files, starts the service) and extensive host reconnaissance: reads /proc/cpuinfo for processor details, invokes `dmidecode --type baseboard` for motherboard/hardware fingerprinting, reads /etc/os-release or /etc/redhat-release for OS identification, checks system uptime, and runs `uname -a` for kernel versioning. It also enumerates running processes, probes for debugger presence (anti-analysis), modifies the local hosts file, and can self-delete to remove forensic traces.

C2 communication rides over plain HTTP GET requests to CGI-style endpoints. The February 2025 sample beacons to a domain pattern `p3.feefreepool[.]net` (evolved from the December 2020 family's `p1.feefreepool[.]net`) at a path resembling `/cgi-bin4rom`, carrying the bot's ID and an embedded/exchanged encryption key. Independent March-April 2025 telemetry from Unit 42 documents a parallel active wave hitting `hxxp://152.36.128[.]18/cgi-bin/p.cgi` for reconnaissance exfiltration and an initial-distribution stage at `hxxp://103.41.204[.]104/k.php?a=x86_64`, hosted on an Apache/PHP server running on a Windows host (ASN 58397, Infinys Network, Jakarta, Indonesia) — consistent with Prometei's historical pattern of C2 infrastructure churn while retaining the same operator TTPs. The 2020-era Windows/Linux campaign additionally used `bk1.bitspiritfun2[.]net` and IP 211.23.16[.]239 as primary C2, with roughly 18 additional C2 URLs spread across US, Germany, and Hong Kong hosting. For resilience against takedown, the malware implements a Domain Generation Algorithm (DGA) to compute fallback C2 domains, and additionally supports Tor and I2P as backup transport/anonymization layers — the February 2025 sample specifically references the I2P address `2oq.b32.i2p`, and the historical Windows branch used a dedicated proxy module (msdtc.exe) for Tor/I2P routing.

Beyond mining, Prometei is a lateral-movement worm: on Windows it drops a modified Mimikatz variant (historically named Miwalk.exe) to dump credentials from memory, an SMB spreader (rdpcIip.exe) that reuses stolen credentials or falls back to the EternalBlue (MS17-010) SMB exploit, and remote-execution helpers using PsExec/WMI. A secondary .NET-based branch (Nvstub) adds an NTLM-based SMB auth tester (ps.exe), a credential-validation bot (nvsync.exe), and an RDP brute-forcing client built on FreeRDP (socks.exe). The primary bot process (historically svchost.exe on Windows) maintains C2 heartbeat while a bundled XMRig-derived module (historically SearchIndexer.exe, XMRig 5.5.3) performs the actual Monero mining. Command-and-control supports operator commands including start_mining and sysinfo, and the family has historically also exploited Microsoft Exchange vulnerabilities for initial access in some campaigns. HTTP C2 traffic is RC4-encrypted with keys exchanged/protected via asymmetric cryptography, consistent with the "enckey" field observed in the JSON configuration trailer of the February 2025 Linux sample. No sector-specific targeting has been identified — victim telemetry spans opportunistic, internet-facing Linux and Windows servers across multiple regions (recent request telemetry: United States, Brazil, Turkey, Pakistan, China, Mexico, Chile).

MITRE ATT&CK techniques used in TL-2026-1490

Credential Access

T1003 OS Credential Dumping; T1110 Brute Force

Lateral Movement

T1021.001 Remote Desktop Protocol; T1021.002 SMB/Windows Admin Shares; T1210 Exploitation of Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027.002 Software Packing; T1036 Masquerading; T1070.004 File Deletion; T1497.003 Time Based Checks; T1564 Hide Artifacts

Persistence

T1053.003 Cron; T1543.002 Systemd Service; T1543.003 Windows Service

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Execution

T1059 Command and Scripting Interpreter; T1569.002 Service Execution

Command and Control

T1071.001 Web Protocols; T1090.003 Multi-hop Proxy; T1105 Ingress Tool Transfer; T1568.002 Domain Generation Algorithms; T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Privilege Escalation

T1078 Valid Accounts

command-and-control

T1090.003 Multi-hop Proxy

Impact

T1496 Resource Hijacking

Affected products and versions in Prometei Botnet (Linux/Prometei.B)

  • Linux — Linux servers (x86_64)
    Vulnerable versions: any internet-facing Linux server with weak/reused SMB, RDP, or brute-forceable credentials
  • Microsoft — Windows Server / SMB / RDP
    Vulnerable versions: unpatched SMBv1 (MS17-010 EternalBlue); RDP-exposed hosts with weak credentials; unpatched Microsoft Exchange
    Fixed in: MS17-010 patched; Exchange with latest CU/security update applied

Remediation for Prometei Botnet (Linux/Prometei.B)

Patches

  • Apply MS17-010 (EternalBlue) if not already patched
  • Apply latest Microsoft Exchange cumulative updates / security patches

Immediate actions

  • Block outbound traffic to known Prometei C2 indicators: p3.feefreepool[.]net, p1.feefreepool[.]net, bk1.bitspiritfun2[.]net, 152.36.128[.]18, 103.41.204[.]104, 211.23.16[.]239
  • Hunt for and remove the cron entries and systemd/service units named uplugplay (Linux) or UPlugPlay pointing at svchost.exe (Windows)
  • Kill and quarantine any process matching known Prometei binary names (uplugplay, svchost.exe when running from non-standard paths, SearchIndexer.exe, msdtc.exe, nvsync.exe, ps.exe, socks.exe, rdpcIip.exe)
  • Rotate all local and domain credentials on hosts showing signs of Mimikatz-style memory credential dumping
  • Block/monitor Tor and I2P egress traffic from server subnets where it is not a legitimate business need, and flag connections to 2oq.b32.i2p

Workarounds

  • Disable SMBv1 where legacy compatibility is not required
  • Restrict outbound HTTP to CGI-style endpoints on non-standard hosting ASNs via egress proxy allow-listing

Longer-term hardening

  • Patch SMB (disable SMBv1 / patch MS17-010 EternalBlue) and any exposed Microsoft Exchange servers
  • Enforce network segmentation to limit SMB/RDP lateral movement between internet-facing and internal hosts
  • Deploy EDR with behavioral detection for cron/systemd persistence creation and unsigned mining-process behavior (sustained high CPU, XMRig-style process trees)
  • Disable or tightly restrict PsExec/WMI remote execution from non-administrative source hosts
  • Enforce RDP MFA and account lockout policies to blunt brute-force credential attacks

Weaknesses (CWE) in Prometei Botnet (Linux/Prometei.B)

CWE-798, CWE-522, CWE-284

Timeline of Prometei Botnet (Linux/Prometei.B)

  • Windows Prometei variant first publicly documented (Cisco Talos), establishing C2 domains bk1.bitspiritfun2[.]net and p1.feefreepool[.]net and modular Mimikatz/SMB-spreader/XMRig architecture.
  • Linux port of Prometei observed in the wild, porting the mining and persistence logic to ELF binaries and introducing cron/uplugplay-style persistence.
  • CUJO AI Vantage publishes 'IoT Malware Journals: Prometei (Linux)', documenting the family's Linux/embedded-device-facing persistence, mining, and worming behavior beyond the original Windows branch.
  • ANY.RUN malware-trends service records active, ongoing Prometei sample submissions and behavioral IOCs ahead of the February 2025 sample's public analysis.
  • Linux/Prometei.B sample (SHA-256 cc7ab872ed9c25d4346b4c58c5ef8ea48c2d7b256f20fe2f0912572208df5c1a) collected, UPX 3.95-packed with a custom JSON configuration trailer, C2 domain pattern shifted to p3.feefreepool[.]net and I2P fallback 2oq.b32.i2p.
  • Researcher cryptax publishes 'Reversing a Prometei botnet binary with r2 and AI (Part One)' detailing Radare2 + r2ai (Claude 3.5 Sonnet) assisted reverse engineering of the sample.
  • Unit 42 telemetry begins tracking a broader March-April 2025 Prometei resurgence wave against Linux servers, including credential theft and brute-forcing modules.
  • Active distribution observed via hxxp://103.41.204[.]104/k.php?a=x86_64 and C2 reconnaissance exfiltration to hxxp://152.36.128[.]18/cgi-bin/p.cgi, hosted on an Apache/PHP server running on a Windows host in ASN 58397 (Jakarta, Indonesia).
  • Unit 42 and Rewterz publish advisories and IOC lists documenting the 2025 Prometei resurgence, including the new C2/distribution infrastructure and self-updating module behavior.
  • Cybersecuritynews, GBHackers, and Cyberpress publish follow-on reporting amplifying the Unit 42/Rewterz 2025 resurgence IOCs and reconnaissance/credential-theft findings to a broader security-practitioner audience.

Sources cited for Prometei Botnet (Linux/Prometei.B)

Detection coverage for TL-2026-1490

As of 2026-02-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1490 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats