PROMETHIUM
Also known as: StrongPity
Overview
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.
Naming & attribution
PROMETHIUM is tracked under 2 names across the industry. It uses 11 documented ATT&CK techniques — more than 32% of the 174 groups tracked here. Activity attributed since at least 2012.
| Name | First reported by |
|---|---|
| StrongPity | Tudorica, R. et al |
| PROMETHIUM | Microsoft |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1205.001Port Knocking — used by 2 of 174 groups -
T1587.002Code Signing Certificates — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
Malware families with current indicators
One family attributed to PROMETHIUM, carrying 9 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- StrongPity 9 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 11 techniques across 6 tactics
Resource Development
-
T1587.002Code Signing Certificates -
T1587.003Digital Certificates
Initial Access
-
T1189Drive-by Compromise
Execution
-
T1204.002Malicious File
Persistence
-
T1543.003Windows Service -
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1036.004Masquerade Task or Service -
T1036.005Match Legitimate Resource Name or Location -
T1078.003Local Accounts -
T1205.001Port Knocking
Defense Impairment
-
T1553.002Code Signing
Tools & malware (2)
Truvasys · StrongPity
Reporting (3)
- StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure — Tudorica, R. et al
- PROMETHIUM extends global reach with StrongPity3 APT — Mercer, W. et al
- Microsoft Security Intelligence Report Volume 21 — Anthe, C. et al