
Prometei Botnet Runs Three Years on SSH Exploits, One C2 Still Live
A 303 KB zero-import Windows implant has been quietly deployed via brute-forced SSH and Telnet services since February 2023, targeting healthcare and telecom organisations. Three independent YARA rulesets and CAPE Sandbox confirm the Prometei family, while one of two C2 domains remains active with wildcard TLS as of June 2026.
A 303-kilobyte Windows executable has been circulating since at least February 2023, quietly fetched by hosts compromised through internet-facing SSH and Telnet services, dropped into a Dell-branded subdirectory under a deliberately misspelled filename, and phoning home to a two-tier command-and-control architecture that spans a now-sinkholed domain and an active fast-flux node still live as of June 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read