Prometei Botnet Targets Windows Servers for Remote Access and Malware Deployment

Prometei Botnet Targets Windows Servers for Remote Access and Malware Deployment

First seen 12 Feb 2026, 00:29 UTC ScworldCyberpressSocprimeCybersecuritynews 42.0

Article Content

Browse articles
ThreatCluster

The Prometei botnet, linked to Russian cybercriminals, is actively targeting Windows Server systems to gain remote access and deploy malware. This modular malware is capable of cryptocurrency mining, credential theft, and lateral movement within networks, exploiting weak or default credentials via Remote Desktop Protocol (RDP). Organizations using Windows Server are at risk of long-term compromise due to this sophisticated attack.

Timeline

2026-02-10
Cyberpress article published on Prometei botnet activity
2026-02-11
Cybersecuritynews article published on Prometei botnet activity