The Prometei botnet, first discovered in 2020, has been spreading its cryptojacking malware and Web shell across multiple continents, infecting over 10,000 computers globally. Despite being around since at least 2016, Prometei remains a significant threat, with a medium-impact rating from Germany's Federal Office for Information Security. Its global reach is attributed to its focus on exploiting widely used software vulnerabilities, particularly in regions with inadequate cybersecurity practices. Prometei's infection process is clunky at first, but stealthy thereafter. It exploits outdated vulnerabilities, such as the "BlueKeep" bug in Remote Desktop Protocol and the EternalBlue vulnerability in Server Message Block. Once inside, it uses a domain generation algorithm to harden its command-and-control infrastructure and manipulates targeted systems to allow its traffic through firewalls. Prometei's ultimate goal is cryptojacking, using infected machines to mine the Monero cryptocurrency without their owners' knowledge. However, it also downloads and configures an Apache Web server, serving as a persistent Web shell that allows attackers to upload more malicious files and execute arbitrary commands. Researchers note that Prometei's approach may seem lazy, but it's an effective way to target neglected systems with multiple security issues. The botnet's ability to evade detection and persist on infected systems makes it a significant threat. Moreover, its links to Russia, including a credential-stealing component that avoids affecting Russian-language targets, suggest a level of sophistication and intent. As one researcher notes, botnet infections like Prometei can be a "canary in the coal mine," indicating that there may be more malicious activity occurring on compromised systems.
IBM released security patches for over 100 vulnerabilities across various products. The biggest sufferers of these patches were Storage Defender, for which patches were issued for ...
Fieldtex Products, a U.S.-based provider of contract sewing and medical supply fulfillment, has reported a data breach following an attack attributed to a well-known ransomware ope...
The Pierce County Library System (PCLS) has announced a major data breach affecting more than 340,000 individuals, including library patrons, employees, former employees, and some ...