# Prometei Botnet (Linux/Prometei.B) — UPX-Packed Monero-Mining Bot with Cron/systemd Persistence, HTTP/DGA C2, and Tor/I2P Fallback

> A February 2025 Linux/Prometei.B botnet sample (SHA-256 cc7ab872ed9c25d4346b4c58c5ef8ea48c2d7b256f20fe2f0912572208df5c1a) was reverse-engineered with Radare2's r2ai extension and Claude 3.5 Sonnet. The UPX-packed ELF x86_64 binary installs as either standard user or root, persists via a cron job and a systemd service named uplugplay, and communicates over HTTP with an appended encrypted-key JSON configuration trailer plus Tor/I2P fallback and DGA-based C2 resilience. Independent March-April 2025 Unit 42 telemetry confirms a broader Prometei resurgence wave targeting Linux servers with credential theft, brute-forcing, and self-updating modules; the family has been active since December 2020 (Linux) / July 2020 (Windows) and mines Monero (XMR) via an embedded XMRig-derived module.

- **Published:** 2026-02-20T00:00:00Z
- **Last reviewed:** 2026-02-20T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1490
- **ID:** TL-2026-1490
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Prometei is a modular, cross-platform (Windows and Linux) botnet first identified in July 2020 (Windows) and December 2020 (Linux), financially motivated and built around Monero (XMR) cryptocurrency mining. This record documents a February 2, 2025 Linux/Prometei.B sample (SHA-256 cc7ab872ed9c25d4346b4c58c5ef8ea48c2d7b256f20fe2f0912572208df5c1a), publicly reverse-engineered by researcher cryptax using Radare2 with the r2ai AI-assisted analysis extension (backed by Claude 3.5 Sonnet via the Anthropic API). The sample is a 64-bit ELF packed with UPX 3.95; standard `upx -d` decompression failed because the malware author appends a custom JSON configuration trailer (fields observed: config, id, enckey, and in newer v3/v4 variants ParentId, ParentHostname, ParentIp, ip) directly after the UPX-compressed payload, which corrupts the UPX footer that unpacking tools rely on and requires the trailer to be manually stripped before standard decompression succeeds. This packing quirk limited the depth of the AI-assisted static analysis in the source writeup (Part One of an ongoing series), leaving several functions and control-flow paths only partially characterized.

Once executed, the dropper copies itself into a persistent location (observed under /usr/sbin as the binary/service name `uplugplay`), and establishes persistence through two redundant mechanisms: a cron job entry and a systemd service unit (also named uplugplay on Linux, mirrored by a Windows service historically named "UPlugPlay" pointing at C:\Windows\svchost.exe in the Windows branch of the family). The installer supports both unprivileged (standard-user) and privileged (root) install paths, broadening the range of initial-access foothold levels it can operationalize. After installation the binary performs systemd bookkeeping (checks service status, reloads systemd unit files, starts the service) and extensive host reconnaissance: reads /proc/cpuinfo for processor details, invokes `dmidecode --type baseboard` for motherboard/hardware fingerprinting, reads /etc/os-release or /etc/redhat-release for OS identification, checks system uptime, and runs `uname -a` for kernel versioning. It also enumerates running processes, probes for debugger presence (anti-analysis), modifies the local hosts file, and can self-delete to remove forensic traces.

C2 communication rides over plain HTTP GET requests to CGI-style endpoints. The February 2025 sample beacons to a domain pattern `p3.feefreepool[.]net` (evolved from the December 2020 family's `p1.feefreepool[.]net`) at a path resembling `/cgi-bin4rom`, carrying the bot's ID and an embedded/exchanged encryption key. Independent March-April 2025 telemetry from Unit 42 documents a parallel active wave hitting `hxxp://152.36.128[.]18/cgi-bin/p.cgi` for reconnaissance exfiltration and an initial-distribution stage at `hxxp://103.41.204[.]104/k.php?a=x86_64`, hosted on an Apache/PHP server running on a Windows host (ASN 58397, Infinys Network, Jakarta, Indonesia) — consistent with Prometei's historical pattern of C2 infrastructure churn while retaining the same operator TTPs. The 2020-era Windows/Linux campaign additionally used `bk1.bitspiritfun2[.]net` and IP 211.23.16[.]239 as primary C2, with roughly 18 additional C2 URLs spread across US, Germany, and Hong Kong hosting. For resilience against takedown, the malware implements a Domain Generation Algorithm (DGA) to compute fallback C2 domains, and additionally supports Tor and I2P as backup transport/anonymization layers — the February 2025 sample specifically references the I2P address `2oq.b32.i2p`, and the historical Windows branch used a dedicated proxy module (msdtc.exe) for Tor/I2P routing.

Beyond mining, Prometei is a lateral-movement worm: on Windows it drops a modified Mimikatz variant (historically named Miwalk.exe) to dump credentials from memory, an SMB spreader (rdpcIip.exe) that reuses stolen credentials or falls back to the EternalBlue (MS17-010) SMB exploit, and remote-execution helpers using PsExec/WMI. A secondary .NET-based branch (Nvstub) adds an NTLM-based SMB auth tester (ps.exe), a credential-validation bot (nvsync.exe), and an RDP brute-forcing client built on FreeRDP (socks.exe). The primary bot process (historically svchost.exe on Windows) maintains C2 heartbeat while a bundled XMRig-derived module (historically SearchIndexer.exe, XMRig 5.5.3) performs the actual Monero mining. Command-and-control supports operator commands including start_mining and sysinfo, and the family has historically also exploited Microsoft Exchange vulnerabilities for initial access in some campaigns. HTTP C2 traffic is RC4-encrypted with keys exchanged/protected via asymmetric cryptography, consistent with the "enckey" field observed in the JSON configuration trailer of the February 2025 Linux sample. No sector-specific targeting has been identified — victim telemetry spans opportunistic, internet-facing Linux and Windows servers across multiple regions (recent request telemetry: United States, Brazil, Turkey, Pakistan, China, Mexico, Chile).

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1569.002 Service Execution
- T1053.003 Cron
- T1543.002 Systemd Service
- T1543.003 Windows Service
- T1078 Valid Accounts
- T1027.002 Software Packing
- T1036 Masquerading
- T1070.004 File Deletion
- T1497.003 Time Based Checks
- T1090.003 Multi-hop Proxy
- T1564 Hide Artifacts
- T1003 OS Credential Dumping
- T1110 Brute Force
- T1082 System Information Discovery
- T1057 Process Discovery
- T1518 Software Discovery
- T1210 Exploitation of Remote Services
- T1021.002 SMB/Windows Admin Shares
- T1021.001 Remote Desktop Protocol
- T1570 Lateral Tool Transfer
- T1071.001 Web Protocols
- T1568.002 Domain Generation Algorithms
- T1090.003 Multi-hop Proxy
- T1573.001 Symmetric Cryptography
- T1573.002 Asymmetric Cryptography
- T1105 Ingress Tool Transfer
- T1496 Resource Hijacking

## Sources

- [Reversing a Prometei botnet binary with r2 and AI (Part One)](https://cryptax.medium.com/reversing-a-prometei-botnet-binary-with-r2-and-ai-part-one-3cdb3dc6ffab)
- [Resurgence of the Prometei Botnet](https://unit42.paloaltonetworks.com/prometei-botnet-2025-activity/)
- [Prometei botnet and its quest for Monero](https://blog.talosintelligence.com/prometei-botnet-and-its-quest-for-monero/)
- [Prometei Botnet Hits Linux for Crypto Mining – Active IOCs](https://rewterz.com/threat-advisory/prometei-botnet-hits-linux-for-crypto-mining-active-iocs)
- [IoT Malware Journals: Prometei (Linux)](https://cujo.com/blog/iot-malware-journals-prometei-linux/)
- [Prometei Malware Analysis, Overview](https://any.run/malware-trends/prometei/)
- [Prometei Botnet Attacking Linux Servers to Mine Cryptocurrency](https://cybersecuritynews.com/prometei-botnet-attacking-linux-servers/)
- [Prometei Botnet Targets Linux Servers for Cryptocurrency Mining Operations](https://gbhackers.com/prometei-botnet-targets-linux-servers/)
- [Linux Servers Exploited by Prometei Botnet for Cryptocurrency Mining](https://cyberpress.org/linux-servers-exploited-by-prometei-botnet/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1490
