C&CMembers
C&C

Debug-Path YARA Rule Unmasks Prometei Botnet Behind OilRig Label

Two files with no shared surface metadata both trigger a crowdsourced YARA rule built for Prometei's compiler debug-path artifacts, and CAPE Sandbox independently tags one as Prometei. A separate SSH-spreader file rounds out a self-propagating botnet toolkit that the upstream feed mislabels as OilRig espionage tooling with a 'ramnit' tag.

Jul 10, 2026, 04:33 (UTC+9)Last seenJul 10, 2026Severity100ByCTX TeamActorOilRigAPT34IOC5MITRE9

Two files land in this cluster carrying almost nothing in common on paper. One is tagged by commercial engines as trojan.prometei/bjsg; the other as trojan.gdvw/leonem. Their import hashes differ entirely, and nothing in their surface metadata suggests a shared origin. Yet both — 39b1042a5b02f3925141733c0f78b64f9fae71a37041c6acc9a9a4e70723a0f1 and ea8cde21792543d7e55dd9a2a894c3cd4fc4fabaeab20ba689b84416c20a6e37 — fire the same crowdsourced YARA rule, Prometei_PDB, a signature built specifically…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence