A stealthier variant of the Prometei botnet is roiling security teams with improved infrastructure and new capabilities. The stepped-up version's primary goal aims to deliver to its victim Monero crypto-mining malware and updated credential theft tools.In a blog post Thursday, Cisco Talos researchers said threat actors are actively spreading an improved third-generation Linux version of the Prometei botnet which it estimates has infected approximately 10,000 systems globally."We have observed previously undocumented functionality, including an alternative C2 domain generating algorithm (DGA), a self-updating mechanism, and a bundled version of the Apache Webserver with a web shell that’s deployed onto victim hosts, improving the overall technical capabilities of the botnet," according to the Cisco report.The Prometei botnet is highly modular and demonstrates worm-like capabilities, Cisco reported. Its primary goal is to deploy the Monero cryptocurrency miner malware. The botnet , "has been continuously improved and updated since it was first seen in 2016, posing a persistent threat to organizations," researchers said. "Prometei is definitely a dangerous threat," said Nick Biasini, head of outreach at Cisco Talos. "It has shown the ability to continuously update its infection mechanisms, anti-analysis techniques, and with this recent addition of a Domain Generation Algorithm and self-updating mechanisms, can evade blocking mechanisms more effectively. The payload may primarily be cryptominers, but the additional ability to steal credentials has become increasingly important in a cybercrime landscape dominated by access brokers."According to Cisco, prior to the Russian invasion of Ukraine, the threat actor behind the botnet mainly avoided targeting Russia and many of its border states. Those efforts now only include avoiding Russia. Cisco Talos reported that it may indicate a desire to limit the infection of and/or communication to any Russian hosts by the botnet’s author – sending the message that previously excluded border states are now fair game.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds