Overview 79 indicators
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.
| domain | 78 | G0056-domain.txt |
| ipv4 | 1 | G0056.json |
Techniques 11 ATT&CK
Open in ATT&CK Navigator → or download the layer (11 techniques, layer 4.5)
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1078.003 Local Accounts
- T1189 Drive-by Compromise
- T1204.002 Malicious File
- T1205.001 Port Knocking
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1553.002 Code Signing
- T1587.002 Code Signing Certificates
- T1587.003 Digital Certificates
Software 2
Principal sources 71 reports
Ranked by how many of this actor's indicators each report brought in.
- 19cybersecurity.att.com/blogs/labs-research/newly-identified-st…
- 19app.any.run/tasks/3ab76ba4-b4ab-4e18-b3b6-9f56e3202…
- 8vxcube.com/recent-threats-ioc/5bf0f120a39bb52be986…
- 6tgsoft.it/english/news_archivio_eng.asp?id=781
- 4virustotal.com/gui/ip-address/139.59.250.183/relations
- 3twitter.com/malwrhunterteam/status/1549125906416943…
- 3welivesecurity.com/2023/01/10/strongpity-espionage-campaig…
- 3virustotal.com/gui/file/be1593bd1f1d5a4d05217f0492832e…
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 79 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
virustotal.com/gui/ip-address/139.59.250.183/relations
hotpatches.net javaplugin-update.com remoteaaddressconnect.com requiredvision.com -
twitter.com/malwrhunterteam/status/1549125906416943… · welivesecurity.com/2023/01/10/strongpity-espionage-campaig… · virustotal.com/gui/file/be1593bd1f1d5a4d05217f0492832e…
intagrefedcircuitchip.com networksoftwaresegment.com -
twitter.com/Des00464472/status/1583333357714538497
inodeapplicationserver.com -
twitter.com/Des00464472/status/1555433330786848771
fairgowingo.com -
twitter.com/Des00464472/status/1351104382943830017
applicationrepo.com -
twitter.com/malwrhunterteam/status/1549125906416943… · welivesecurity.com/2023/01/10/strongpity-espionage-campaig… · virustotal.com/gui/file/be1593bd1f1d5a4d05217f0492832e…
dutchvideochatting.com -
virustotal.com/gui/file/ef156165bdefe2a90c83e787218a67… · virustotal.com/gui/file/d8e09efe37e802b6541b97b22ca49d…
sessionprotocol.com -
twitter.com/RedDrip7/status/1430716604896010243 · virustotal.com/gui/file/c278454e57783e327ec452a418ccc1… · virustotal.com/gui/file/7b6d5d611d70dade1b90c10d2dfced…
repositoryupdating.com -
anchorednarratives.substack.com/p/recover-your-files-with-strongpity · virustotal.com/gui/file/1887977dc8ea476b5ddacccfe74e6c… · virustotal.com/gui/file/2b26f4ce23dea823f4f7f8daf4c815… · virustotal.com/gui/file/786c58acaf7a1354b0038f34adec8a…
fileaccesscontrol.com networkmanagemersolutions.com -
twitter.com/BaoshengbinCumt/status/1400271045576192… · virustotal.com/gui/file/84621560ab59aff0d63ab521d6eea3…
selectednewfile.com -
twitter.com/BaoshengbinCumt/status/1399652333210923… · virustotal.com/gui/file/d22c6046f7c1102da9f60162f5529a… · virustotal.com/gui/file/a9ed18bf798d32dcb7e9203720c35c… · virustotal.com/gui/file/f8671aedf3691b8bd5765fadfdb286… · virustotal.com/gui/file/f1552d049c3cae1a81be859cb8cd0c…
filedocumentmanager.com -
twitter.com/silv0123/status/1394124776080240640 · virustotal.com/gui/file/debf8937623397e35359cd8e758283…
informationserviceslab.com -
virustotal.com/gui/file/eef5205cce36d1613036ce4ece3875…
cdn12-web-security.com -
virustotal.com/gui/file/50baf0ea166f7e578b19fa519a6050…
ms-health-monitor.com -
twitter.com/voodoodahl1/status/1371538406984007683
hardwareoption.com hierarchicalfiles.com pulmonyarea.com -
twitter.com/_re_fox/status/1371197939599749123 · virustotal.com/gui/file/b6e3018d7b5f4aef74bcbd38b86ec5…
transfermychoice.com -
twitter.com/silv0123/status/1370339230329696260 · virustotal.com/gui/file/0e4651625abda88df56952b7e97d7f…
resolutionplatform.com -
twitter.com/silv0123/status/1368589447780954113 · virustotal.com/gui/file/057e27d215f4930469417bfd5fec41…
lurkingnet.com -
cybleinc.com/2020/12/31/strongpity-apt-extends-globa… · virustotal.com/gui/ip-address/185.47.131.103/relations
hybirdcloudreportingsoftware.com -
twitter.com/BaoshengbinCumt/status/1344270106201784… · virustotal.com/gui/file/4efa6bc5ffe7b39a4e7f674e081e64…
findingpcdrivers.com -
twitter.com/BaoshengbinCumt/status/1342761047967481… · virustotal.com/gui/file/1185998fd595936708c1fc5a3ddead…
uppertrainingtool.com -
twitter.com/BaoshengbinCumt/status/1333583293636255… · virustotal.com/gui/file/4f4efb22c0bdd0bd8d1af525594571…
updserv-east-cdn3.com -
twitter.com/BaoshengbinCumt/status/1333302456185339… · virustotal.com/gui/file/0265e9f22753a574dcc0f20fdb1838… · virustotal.com/gui/file/0f4933ae0b67f03154f36c3e47acd5…
ms-cdn-88.com -
twitter.com/BaoshengbinCumt/status/1330056911195136…
transferprotocolpolicy.com -
twitter.com/BaoshengbinCumt/status/1313717536865742… · virustotal.com/gui/file/04c6b2e93ee33d4b12f61c565ef164… · virustotal.com/gui/file/2ea1ff8dc4a5ea276f8ae4137cbce0… · virustotal.com/gui/file/3da5ad345fa5dc65c5313a0846897b…
cerulearc.com protectapplication.com record-fords.cerulearc.com -
twitter.com/voodoodahl1/status/1265340234054668289
mailtransfersagents.com mentiononecommon.com ms21-app3-upload.com -
twitter.com/malwrhunterteam/status/1264137361446899… · twitter.com/0xthreatintel/status/1355847489291603970 · 0xthreatintel.medium.com/uncovering-apt-c-41-strongpity-backdoor… · virustotal.com/gui/ip-address/91.219.238.31/relations · twitter.com/BaoshengbinCumt/status/1344620693086904… · virustotal.com/gui/file/f81d16d98d7c5423e8f231fe47778b…
hostoperationsystems.com -
cybersecurity.att.com/blogs/labs-research/newly-identified-st… · app.any.run/tasks/3ab76ba4-b4ab-4e18-b3b6-9f56e3202…
apn-state-upd2.com app-mx3-delivery.com cdn2-state-upd.com cdn2-svr-state.com cdn4-rxe3-map.com mx-upd2-cdn-state.com oem-sec4-mx32.com srv-cdn3-system.com srv5-upd51-mx3-sec22.com svr-sec2-system.com sys4-upload2-srv.com system6-mxe-ups3.com upd-ncx4-server.com upd-network-ms2.com upd-secure-srv1.com upd2-app-state.com upd3-srv-system-app.com upd56-state3-cdn7-mx8.com upn-sec3-msd.com -
twitter.com/Vishnyak0v/status/1229725292513636353
syse-update-app4.com -
twitter.com/kyleehmke/status/1227950151140073472
node1-cdn-network.com -
twitter.com/CTI_Marc/status/1221809588925800449
serv3-app-system4.com -
vxcube.com/recent-threats-ioc/5bf0f120a39bb52be986…
edicupd002.com ftp.mynetenergy.com srv601.ddns.net srv602.ddns.net svnservices.com updatesync.com windriversupport.com -
tgsoft.it/english/news_archivio_eng.asp?id=781
myrappid.com mytoshba.com pinkturtle.me ralrab.com true-crypte.website -
twitter.com/kyleehmke/status/1220738826513063942 · app.any.run/tasks/6ae5416b-fc75-405f-8888-71d5f6c7d…
ms6-upload-serv3.com state-awe3-apt.com -
tgsoft.it/english/news_archivio_eng.asp?id=781 · vxcube.com/recent-threats-ioc/5bf0f120a39bb52be986…
truecrypte.org -
virustotal.com/gui/file/80ad6598f6e0b7c2b7258cbb69aa78…
193.235.207.60:443 -
twitter.com/Vishnyak0v/status/1219590822204727296
apt5-secure3-state.com -
twitter.com/VK_Intel/status/1189939324344766464 · virustotal.com/gui/file/b75fbe3b21d83e2000928349d1610f…
upd32-secure-serv4.com -
proofpoint.com/us/daily-ruleset-update-summary-20180522
ms-sys-security.com
Further reading 76
- download.microsoft.com/download/E/B/0/EB0F50CC-989C-4B66-B7F6-…
- attack.mitre.org/groups/G0056
- blog.talosintelligence.com/2020/06/promethium-extends-with-strongp…
- blogs.technet.microsoft.com/mmpc/2016/12/14/twin-zero-day-attacks-p…
- bitdefender.com/files/News/CaseStudies/study/353/Bitdef…
- virustotal.com/gui/file/1185998fd595936708c1fc5a3ddead…
- virustotal.com/gui/file/f8671aedf3691b8bd5765fadfdb286…
- twitter.com/Des00464472/status/1583333357714538497
- virustotal.com/gui/file/b75fbe3b21d83e2000928349d1610f…
- tgsoft.it/english/news_archivio_eng.asp?id=781
- twitter.com/BaoshengbinCumt/status/1313717536865742…
- virustotal.com/gui/file/0f4933ae0b67f03154f36c3e47acd5…
- virustotal.com/gui/file/3da5ad345fa5dc65c5313a0846897b…
- twitter.com/_re_fox/status/1371197939599749123
- twitter.com/BaoshengbinCumt/status/1400271045576192…
- virustotal.com/gui/file/4efa6bc5ffe7b39a4e7f674e081e64…
- virustotal.com/gui/file/2ea1ff8dc4a5ea276f8ae4137cbce0…
- twitter.com/Vishnyak0v/status/1219590822204727296
- cybleinc.com/2020/12/31/strongpity-apt-extends-globa…
- cybersecurity.att.com/blogs/labs-research/newly-identified-st…
- twitter.com/BaoshengbinCumt/status/1333302456185339…
- virustotal.com/gui/file/eef5205cce36d1613036ce4ece3875…
- virustotal.com/gui/file/c278454e57783e327ec452a418ccc1…
- twitter.com/VK_Intel/status/1189939324344766464
- twitter.com/silv0123/status/1370339230329696260
- twitter.com/kyleehmke/status/1227950151140073472
- virustotal.com/gui/file/d22c6046f7c1102da9f60162f5529a…
- virustotal.com/gui/file/1887977dc8ea476b5ddacccfe74e6c…
- virustotal.com/gui/file/7b6d5d611d70dade1b90c10d2dfced…
- virustotal.com/gui/file/057e27d215f4930469417bfd5fec41…
- proofpoint.com/us/daily-ruleset-update-summary-20180522
- virustotal.com/gui/file/4f4efb22c0bdd0bd8d1af525594571…
- twitter.com/BaoshengbinCumt/status/1342761047967481…
- twitter.com/0xthreatintel/status/1355847489291603970
- welivesecurity.com/2023/01/10/strongpity-espionage-campaig…
- virustotal.com/gui/file/786c58acaf7a1354b0038f34adec8a…
- virustotal.com/gui/ip-address/139.59.250.183/relations
- virustotal.com/gui/file/d8e09efe37e802b6541b97b22ca49d…
- virustotal.com/gui/ip-address/91.219.238.31/relations
- 0xthreatintel.medium.com/uncovering-apt-c-41-strongpity-backdoor…
36 more, and the report behind every indicator, in G0056.json.