PROMETHIUM
Also reported as StrongPity, APT-C-41, Magenta Dust, Promethium and SmallPity. Linked to Turkey by four sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2008-2551
- CVE-2010-0188 KEV ransomware
- CVE-2010-0840 KEV
- CVE-2010-1297 KEV
- CVE-2010-2568 KEV
- CVE-2010-3336
- CVE-2010-3653
- CVE-2011-0097
- CVE-2011-0611 KEV
- CVE-2011-1823 KEV
- CVE-2012-0056
- CVE-2012-0158 KEV ransomware
Show all 71 CVEs Show fewer
- CVE-2012-0507 KEV ransomware
- CVE-2012-1723 KEV ransomware
- CVE-2012-1823 KEV
- CVE-2012-1889 KEV
- CVE-2012-2311
- CVE-2013-0074 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2013-1493
- CVE-2013-2423 KEV
- CVE-2013-2460
- CVE-2013-2551 KEV ransomware
- CVE-2013-3896 KEV
- CVE-2014-1761 KEV
- CVE-2014-6332 KEV
- CVE-2015-0072
- CVE-2015-0310 KEV
- CVE-2015-0311 KEV
- CVE-2015-0313 KEV
- CVE-2015-1671 KEV
- CVE-2015-5119 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0165 KEV
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1010 KEV
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2017-0199192
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-17215
- CVE-2018-0798 KEV
- CVE-2018-1010
- CVE-2018-1012
- CVE-2018-1013
- CVE-2018-1015
- CVE-2018-11776 KEV
- CVE-2018-14787
- CVE-2018-4876
- CVE-2018-4878 KEV ransomware
- CVE-2018-7445 KEV
- CVE-2018-8174 KEV ransomware
- CVE-2018-8174507
- CVE-2018-8453 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2023-38831 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Promethium, StrongPity - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Promethium, StrongPity - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oblique RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SUNBURST (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ave Maria (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Agent Tesla (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor WastedLocker (Malware Family)
Show all 58 reports Show fewer
-
StrongPity espionage campaign targeting Android users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor StrongPity espionage campaign targeting Android users
-
Analysis of Attack Activity of PROMETHIUM Disguised
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Attack Activity of PROMETHIUM Disguised
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyberspace's Magic Eye- PROMETHIUM Fakes attack activity analysis of NotePads and installation packages
-
FINDING BEACONS IN THE DARK 1650728751599
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FINDING BEACONS IN THE DARK 1650728751599
-
Hunter Becomes Hunted- Zebra2104 Hides a Herd of Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunter Becomes Hunted- Zebra2104 Hides a Herd of Malware
-
StrongPity APT Group Deploys Android Malware for the First Time
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor StrongPity APT Group Deploys Android Malware for the First Time
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking StrongPity with Yara
-
Recover your files with StrongPity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Recover your files with StrongPity
-
StrongPity APT Extends Global Reach with New Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor StrongPity APT Extends Global Reach with New Infrastructure
-
蓝色魔眼(APT-C-41)组织首次针对我国重要机构定向攻击活动披露
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 蓝色魔眼(APT-C-41)组织首次针对我国重要机构定向攻击活动披露
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-APTHackers-creat4740-en_EN:Bitdefender-PR-Whitepaper-APTHackers-creat4740-en_EN.indd
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-StrongPity_APT-creat4574-en_EN:Bitdefender-PR-Whitepaper-StrongPity_APT-creat4574-en_EN.indd
-
PROMETHIUM extends global reach with StrongPity3 APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PROMETHIUM extends global reach with StrongPity3 APT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Talos Blog __ Cisco Talos Intelligence Group - Comprehensive Threat Intelligence_ PROMETHIUM extends global reach with StrongPity3 APT
-
Newly identified StrongPity operations _ AT&T Alien Labs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Newly identified StrongPity operations _ AT&T Alien Labs
-
Ransomware REvil - Sodinokibi- Technical analysis and Threat Intelligence Report
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware REvil - Sodinokibi- Technical analysis and Threat Intelligence Report
-
ENISA Threat Landscape Report 2018
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ENISA Threat Landscape Report 2018
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Trends report Q1 2018
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sandvine’s PacketLogic Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor BAD TRAFFIC_ Sandvine’s PacketLogic Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads_
-
StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved-
-
PROMETHIUM and NEODYMIUM: Parallel zero-day attacks targeting individuals in Europe
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor PROMETHIUM and NEODYMIUM: Parallel zero-day attacks targeting individuals in Europe
-
Twin zero-day attacks- PROMETHIUM and NEODYMIUM target individuals in Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Twin zero-day attacks- PROMETHIUM and NEODYMIUM target individuals in Europe
-
Microsoft_Security_Intelligence_Report_Volume_21_English
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft_Security_Intelligence_Report_Volume_21_English
-
On the StrongPity Waterhole Attacks - Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor On the StrongPity Waterhole Attacks - Securelist
-
On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
-
On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
Newest first. Details opens the report in Explore.