Hackers are attempting to exploit vulnerabilities in Microsoft Exchange servers, aiming to add them to their botnet for cryptocurrency mining. Given the level of access the hackers gain, they could use it to carry out other, much more dangerous cyberattacks.
The botnet in question is called “Prometei” and according to security researchers at Cybereason, it is a global malicious campaign that targets organizations in a multi-stage attack.
The hackers behind the Prometei botnet exploit vulnerabilities in Microsoft Exchange servers to infiltrate networks. Security updates are available to protect against attacks, but Prometei scans the Internet to find organizations that have not yet applied patches, and gain access to networks.

Read also: Hackers install cryptomining malware on unpatched Microsoft Exchange servers
Prometei does not target a specific organization. Attackers simply look for vulnerable networks that they can exploit. According to researchers, the botnet lists victims in industries across regions, including North and South America, Europe, and East Asia.
The attackers' main goal is to install cryptojacking malware to mine Monero.
Prometei exploits vulnerabilities in Microsoft Exchange servers to gain initial access to a network and attempts to infect as many endpoints – using a variety of known attack techniquesto move laterally through the network.
See also: Black Kingdom ransomware: Targets Microsoft Exchange servers. Greece among the victims
Techniques include harvesting login credentials, exploiting RDP vulnerabilities, and using older exploits, including EternalBlue and BlueKeep, to compromise as many machines as possible. EternalBlue and BlueKeep have been patched, as have the Microsoft Exchange Server vulnerabilities, but attackers can still exploit organizations that have not implemented them on their networks.

Additionally, the researchers point out that the hackers behind Prometei appear to want to achieve long-term persistence on a network, which they do using techniques associated with sophisticated cybercriminal operations and even state-run hacking groups. Prometei is currently focused on cryptocurrency mining.
Assaf Dahan, head of threat research at Cybereason, said: “The longer they manage to stay on a network, the more cryptocurrencies they can mine. Therefore, hackers improved the resilience of the botnet, added “stealth” capabilities to the malware, while also using techniques and tools often associated with APT (Advanced Persistent Threats) groups. If they wanted, the attackers could also infect the compromised endpoints with other malware, as well as collaborate with ransomware gangs to sell access to the endpoints.”
Proposal: Matryosh botnet: Targets Android-based devices for DDoS attacks!

Not much is known about the criminal enterprise behind Prometei, but according to Cybereason's analysis of the group's activity, the hackers speak Russian and appear to avoid infecting targets in Russia.
The botnet name “Prometei” is the Russian word for Prometheus, the titan who gave fire to humans according to Greek mythology. It is estimated that Prometei is still looking for new targets to infect. The best way to avoid falling victim is to apply the critical security updates that have been released for Microsoft Exchange Server.
Finally, Dahan stressed that organizations should, first and foremost, strive to have a good code management process and patch potentially vulnerable systems . But more importantly , security and IT teams should prevent such incidents and constantly "hunt" for known threats.
Information source: zdnet.com
