Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

U.S. CFTC’s Selig says AI has helped make up for staffing cuts at key crypto watchdog

April 16, 2026

Public crypto miners sold more BTC in Q1 2026 than all of 2025: Report

April 16, 2026

SEC Approves Elimination of Pattern Day Trader Rule and $25,000 Minimum: FINRA

April 16, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Prometei Botnet Exploits Exchange Server Bugs to Grow
Prometei Botnet Exploits Exchange Server Bugs to Grow
Security and Privacy

Prometei Botnet Exploits Exchange Server Bugs to Grow

July 15, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers have discovered that a persistent cryptocurrency mining botnet is exploiting still-unpatched Microsoft Exchange servers to grow globally.

Dubbed “Prometei,” the botnet was first reported on in July 2020 and is thought to have been around since 2016, according to Cybereason Nocturnus.

However, the research team found a new development in that the threat actors behind it have been exploiting Microsoft Exchange vulnerabilities CVE-2021-27065 and CVE-2021-26858 to penetrate victim networks, steal credentials and install malware.

These bugs are part of the four zero-days patched by Microsoft back in March after being exploited by Chinese APT group Hafnium.

“The victimology is quite random and opportunistic rather than highly targeted, which makes it even more dangerous and widespread. Prometei has been observed to be active in systems across a variety of industries, including: finance, insurance, retail, manufacturing, utilities, travel, and construction,” senior threat researcher Lior Rochberger of Cybereason noted in a blog post today.

“It has been observed infecting networks in the US, UK and many other European countries, as well as countries in South America and East Asia. It was also observed that the threat actors appear to be explicitly avoiding infecting targets in former Soviet bloc countries.”

After initial exploitation, the botnet is designed to spread across the network in order to install a Monero miner on as many endpoints as possible. To do this, it uses tried-and-tested exploits EternalBlue and BlueKeep, as well as harvesting credentials, and exploiting SMB and RDP alongside other components such as SSH client and SQL spreader, Rochberger said.

Four separate command-and-control (C&C) servers add resilience and make it harder to disrupt the botnet, he added. Prometei is also designed to use Windows or Linux payloads to compromise individual endpoints depending on their OS.

See also  SEC Sues Former FTX Crypto Exchange Auditor 

Assaf Dahan, Cybereason senior director and head of threat research, argued that the botnet poses a serious risk as it has been under-reported in the past.

“When the attackers take control of infected machines, they are not only capable of mining bitcoin by stealing processing power, but could exfiltrate sensitive information as well,” he added.

“If they desire to do so, the attackers could also infect the compromised endpoints with other malware and collaborate with ransomware gangs to sell access to the endpoints. To make matters worse, crypto-mining drains valuable network computing power, negatively impacting business operations and the performance and stability of critical servers.”

Source link

Botnet Bugs Exchange exploits grow Prometei Server
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Lido [LDO] surges 13% as exchange supply drops – What happens next?

April 16, 2026

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

Kraken is actively being extorted by criminals threatening to release the top crypto exchange’s internal data

April 14, 2026

Operation Atlantic Seizes $12m in Crypto Losses

April 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

$349M liquidations in 24 hours: Is the crypto market in panic mode?

April 2, 2026

Will Bitcoin Guide Shiba Inu (SHIB) to Recovery?

July 14, 2024

Home Bitcoin Mining is Going To Heat Europe

August 16, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

U.S. CFTC’s Selig says AI has helped make up for staffing cuts at key crypto watchdog

April 16, 2026

Public crypto miners sold more BTC in Q1 2026 than all of 2025: Report

April 16, 2026

SEC Approves Elimination of Pattern Day Trader Rule and $25,000 Minimum: FINRA

April 16, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$74,918.000.33%
  • ethereumEthereum(ETH)$2,340.56-0.55%
  • tetherTether(USDT)$1.00-0.02%
  • rippleXRP(XRP)$1.454.62%
  • binancecoinBNB(BNB)$633.641.63%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$88.945.34%
  • tronTRON(TRX)$0.327141-0.32%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.28%
  • dogecoinDogecoin(DOGE)$0.0984413.94%