PROMETHIUM
Aliases: StrongPity
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.
Open interactive actor investigation
ATT&CK techniques
T1204.002
Malicious FileT1587.002
Code Signing CertificatesT1078.003
Local AccountsT1587.003
Digital CertificatesT1547.001
Registry Run Keys / Startup FolderT1543.003
Windows ServiceT1036.005
Match Legitimate Name or LocationT1036.004
Masquerade Task or ServiceT1553.002
Code SigningT1205.001
Port KnockingT1189
Drive-by Compromise
Malicious FileT1587.002
Code Signing CertificatesT1078.003
Local AccountsT1587.003
Digital CertificatesT1547.001
Registry Run Keys / Startup FolderT1543.003
Windows ServiceT1036.005
Match Legitimate Name or LocationT1036.004
Masquerade Task or ServiceT1553.002
Code SigningT1205.001
Port KnockingT1189
Drive-by Compromise