NEODYMIUM

MITRE ATT&CK: G0055 View on attack.mitre.org

Aliases: NEODYMIUM

First seen
2016-05-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-06-18 18:55:18
Profile updated
2026-07-07 12:33:37

Targeted industries: government-and-public-sector energy-and-utilities media-and-entertainment

Targeted regions: country_code:tr

Context

NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to overlapping victim and campaign characteristics. NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.

Malware & tools used

Reports & references

  • Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
  • MITRE ATT&CK — G0055 (report)
  • cyberscoop.com — Middle Eastern Hacking Group Using Finfisher Malware Conduct International Espionage (report)
  • Microsoft — Microsoft Security Intelligence Report Volume 21 English (report)

External references