PROMETHIUM

MITRE ATT&CK: G0056 View on attack.mitre.org

Aliases: StrongPity, PROMETHIUM, SmallPity

First seen
2012-01-01 00:00:00
Origin
TR
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
4 (2 malicious)
Last IoC activity
2025-12-29 00:36:41
Profile updated
2026-07-07 12:33:59

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:tr country_code:it country_code:be country_code:es

Context

PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to PROMETHIUM (G0056). The 7 most recently updated:

Detection coverage

  • 3 YARA rules
  • 120 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Code Signing Certificates (attack-pattern)
  • Local Accounts (attack-pattern)
  • Digital Certificates (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Windows Service (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Code Signing (attack-pattern)
  • Port Knocking (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • StrongPity (malware)
  • Truvasys (malware)

Reports & references

  • Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
  • virusbulletin.com — Last Minute Paper Strongpity Waterhole Attacks Targeting Italian And Belgian Encryption Users (report)
  • MITRE ATT&CK — G0056 (report)
  • Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Security Intelligence Report Volume 21 English (report)
  • Cisco Talos — Promethium Extends With Strongpity3 (report)
  • bitdefender.com — Bitdefender Whitepaper Strongpity Apt (report)

Attributed from

  • C0033 (campaign)

External references