StrongPity
MITRE ATT&CK: S0491 View on attack.mitre.org
Aliases: StrongPity
- First seen
- 2016-06-01 00:00:00
- Malware type
- spyware, credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2025-07-21 15:17:31
- Profile updated
- 2026-07-07 12:38:23
Targeted industries: government-and-public-sector
Targeted regions: country_code:tr country_code:it country_code:be
Context
StrongPity is an information stealing malware used by PROMETHIUM.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to StrongPity (S0491). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | https://system6-mxe-ups3.com/p5Pss34GvX21pxO0bz25vLqU.php | 2025-07-21 | 1 |
| URL | https://system6-mxe-ups3.com/goN9Z2In7mYQmN92dzX11CQL.php | 2025-07-21 | 1 |
| URL | https://srv-cdn3-system.com/p5Pss34GvX21pxO0bz25vLqU.php | 2025-07-14 | 1 |
| URL | https://srv-cdn3-system.com/goN9Z2In7mYQmN92dzX11CQL.php | 2025-07-14 | 1 |
Detection coverage
- 3 YARA rules
- 673 Sigma rules
Malware & tools used
- Automated Exfiltration (attack-pattern)
- Hidden Window (attack-pattern)
- Non-Standard Port (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Malicious File (attack-pattern)
- Web Protocols (attack-pattern)
- File Deletion (attack-pattern)
- Security Software Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- PowerShell (attack-pattern)
- Windows Service (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Process Discovery (attack-pattern)
- Service Execution (attack-pattern)
- Code Signing (attack-pattern)
Used by threat actors
- PROMETHIUM (threat-actor)
- C0033 (campaign)
Detection rules
- DITEKSHEN_MALWARE_Win_Strongpity (yara-rule)
- SEKOIA_Strongpity_Malware (yara-rule)
- SEKOIA_Spyware_And_Strongpity_Mobile_Backdoor (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Cisco Talos — Promethium Extends With Strongpity3 (report)
- bitdefender.com — Bitdefender Whitepaper Strongpity Apt (report)
- Cisco Talos — 2020 Year In Malware (report)
- blogs.blackberry.com — Zebra2104 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Strongpity (report)
- anchorednarratives.substack.com — Recover Your Files With Strongpity (report)
- blog.minerva-labs.com — A New Strongpity Variant Hides Behind Notepad Installation (report)
- mp.weixin.qq.com — 5No0Tr4Ecvpp Xv4Joxebg (report)
- anchorednarratives.substack.com — Tracking Strongpity With Yara (report)
- mp.weixin.qq.com — Nqvukiwkiqtj2Planyheoa (report)
- cybleinc.com — Strongpity Apt Extends Global Reach With New Infrastructure (report)
- Kaspersky — On The Strongpity Waterhole Attacks Targeting Italian And Belgian Encryption Users (report)
- ti.qianxin.com — Promethium Attack Activity Analysis Disguised As Winrar.Exe (report)
- twitter.com — 786293008278970368 (report)
- citizenlab.ca — Bad Traffic Sandvines Packetlogic Devices Deploy Government Spyware Turkey Syria (report)
- 0xthreatintel.medium.com — Uncovering Apt C 41 Strongpity Backdoor E7F9A7A076F4 (report)
- ESET — Strongpity Like Spyware Replaces Finfisher (report)
- MITRE ATT&CK — S0491 (report)