PROMETHIUM
MITRE ATT&CK: G0056 View on attack.mitre.org
Aliases: StrongPity, PROMETHIUM, SmallPity
- First seen
- 2012-01-01 00:00:00
- Origin
- TR
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 4 (2 malicious)
- Last IoC activity
- 2025-12-29 00:36:41
- Profile updated
- 2026-07-07 12:33:59
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:tr country_code:it country_code:be country_code:es
Context
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.
Recent IoC activity
7 malicious indicators in Maltiverse are attributed to PROMETHIUM (G0056). The 7 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | system6-mxe-ups3.com | 2026-09-03 | 2 |
| URL | https://srv-cdn3-system.com/goN9Z2In7mYQmN92dzX11CQL.php | 2026-09-03 | 1 |
| URL | https://system6-mxe-ups3.com/p5Pss34GvX21pxO0bz25vLqU.php | 2026-09-03 | 1 |
| URL | https://system6-mxe-ups3.com/goN9Z2In7mYQmN92dzX11CQL.php | 2026-09-03 | 1 |
| URL | https://srv-cdn3-system.com/p5Pss34GvX21pxO0bz25vLqU.php | 2026-09-03 | 1 |
| URL | https://apn-state-upd2.com/p5Pss34GvX21pxO0bz25vLqU.php | 2025-09-18 | 1 |
| URL | https://apn-state-upd2.com/goN9Z2In7mYQmN92dzX11CQL.php | 2025-09-18 | 1 |
Detection coverage
- 3 YARA rules
- 120 Sigma rules
Malware & tools used
- Malicious File (attack-pattern)
- Code Signing Certificates (attack-pattern)
- Local Accounts (attack-pattern)
- Digital Certificates (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Service (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Code Signing (attack-pattern)
- Port Knocking (attack-pattern)
- Drive-by Compromise (attack-pattern)
- StrongPity (malware)
- Truvasys (malware)
Reports & references
- Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
- virusbulletin.com — Last Minute Paper Strongpity Waterhole Attacks Targeting Italian And Belgian Encryption Users (report)
- MITRE ATT&CK — G0056 (report)
- Microsoft — Twin Zero Day Attacks Promethium And Neodymium Target Individuals In Europe (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Security Intelligence Report Volume 21 English (report)
- Cisco Talos — Promethium Extends With Strongpity3 (report)
- bitdefender.com — Bitdefender Whitepaper Strongpity Apt (report)
Attributed from
- C0033 (campaign)