NEODYMIUM
MITRE ATT&CK: G0055 View on attack.mitre.org
Aliases: NEODYMIUM
- First seen
- 2016-05-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-18 18:55:18
- Profile updated
- 2026-07-07 12:33:37
Targeted industries: government-and-public-sector energy-and-utilities media-and-entertainment
Targeted regions: country_code:tr
Context
NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to overlapping victim and campaign characteristics. NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.
Malware & tools used
- Wingbird (malware)
Reports & references
- Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
- MITRE ATT&CK — G0055 (report)
- cyberscoop.com — Middle Eastern Hacking Group Using Finfisher Malware Conduct International Espionage (report)
- Microsoft — Microsoft Security Intelligence Report Volume 21 English (report)