C&CMembers
C&C

Prometei Botnet Runs Three Years on SSH Exploits, One C2 Still Live

A 303 KB zero-import Windows implant has been quietly deployed via brute-forced SSH and Telnet services since February 2023, targeting healthcare and telecom organisations. Three independent YARA rulesets and CAPE Sandbox confirm the Prometei family, while one of two C2 domains remains active with wildcard TLS as of June 2026.

Jun 2, 2026, 08:31 (UTC+9)Last seenJun 2, 2026Severity100ByCTX TeamActorOilRigAPT34IOC7MITRE9

A 303-kilobyte Windows executable has been circulating since at least February 2023, quietly fetched by hosts compromised through internet-facing SSH and Telnet services, dropped into a Dell-branded subdirectory under a deliberately misspelled filename, and phoning home to a two-tier command-and-control architecture that spans a now-sinkholed domain and an active fast-flux node still live as of June 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence