StrongPity

MITRE ATT&CK: S0491 View on attack.mitre.org

Aliases: StrongPity

First seen
2016-06-01 00:00:00
Malware type
spyware, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
4 (4 malicious)
Last IoC activity
2025-07-21 15:17:31
Profile updated
2026-07-07 12:38:23

Targeted industries: government-and-public-sector

Targeted regions: country_code:tr country_code:it country_code:be

Context

StrongPity is an information stealing malware used by PROMETHIUM.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to StrongPity (S0491). The 4 most recently updated:

Detection coverage

  • 3 YARA rules
  • 673 Sigma rules

Malware & tools used

  • Automated Exfiltration (attack-pattern)
  • Hidden Window (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Malicious File (attack-pattern)
  • Web Protocols (attack-pattern)
  • File Deletion (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Service (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Process Discovery (attack-pattern)
  • Service Execution (attack-pattern)
  • Code Signing (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Strongpity (yara-rule)
  • SEKOIA_Strongpity_Malware (yara-rule)
  • SEKOIA_Spyware_And_Strongpity_Mobile_Backdoor (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • Cisco Talos — Promethium Extends With Strongpity3 (report)
  • bitdefender.com — Bitdefender Whitepaper Strongpity Apt (report)
  • Cisco Talos — 2020 Year In Malware (report)
  • blogs.blackberry.com — Zebra2104 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Strongpity (report)
  • anchorednarratives.substack.com — Recover Your Files With Strongpity (report)
  • blog.minerva-labs.com — A New Strongpity Variant Hides Behind Notepad Installation (report)
  • mp.weixin.qq.com — 5No0Tr4Ecvpp Xv4Joxebg (report)
  • anchorednarratives.substack.com — Tracking Strongpity With Yara (report)
  • mp.weixin.qq.com — Nqvukiwkiqtj2Planyheoa (report)
  • cybleinc.com — Strongpity Apt Extends Global Reach With New Infrastructure (report)
  • Kaspersky — On The Strongpity Waterhole Attacks Targeting Italian And Belgian Encryption Users (report)
  • ti.qianxin.com — Promethium Attack Activity Analysis Disguised As Winrar.Exe (report)
  • twitter.com — 786293008278970368 (report)
  • citizenlab.ca — Bad Traffic Sandvines Packetlogic Devices Deploy Government Spyware Turkey Syria (report)
  • 0xthreatintel.medium.com — Uncovering Apt C 41 Strongpity Backdoor E7F9A7A076F4 (report)
  • ESET — Strongpity Like Spyware Replaces Finfisher (report)
  • MITRE ATT&CK — S0491 (report)

External references