AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
PROMETHIUM
Aliases: StrongPity
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.
Open interactive actor investigation
ATT&CK techniques
Malicious FileT1587.002
Code Signing CertificatesT1078.003
Local AccountsT1587.003
Digital CertificatesT1547.001
Registry Run Keys / Startup FolderT1543.003
Windows ServiceT1036.005
Match Legitimate Name or LocationT1036.004
Masquerade Task or ServiceT1553.002
Code SigningT1205.001
Port KnockingT1189
Drive-by Compromise
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Red Team & Offensive Security · explicit-nameModule 3 — Vulnerability discovery and validation
Red Team & Offensive Security · topic-matchMobile and Android vulnerability research
Vulnerability Research & Exploit Development · topic-matchHuman, workload, pipeline, and emergency identity
Cloud Security · topic-matchModule 13 — Red-team infrastructure and operations
Red Team & Offensive Security · topic-matchFile identity, containers, and executable formats
Malware Analysis & Reverse Engineering · topic-matchAndroid malware and mobile application behavior
Malware Analysis & Reverse Engineering · topic-matchRequirements, ownership, inventory, and data flow
Secure Code & Application Security · topic-matchNetwork behavior, protocols, and configuration recovery
Malware Analysis & Reverse Engineering · topic-matchScenario-based cyber risk assessment and treatment
Governance, Risk & Compliance (GRC) · topic-matchOperational resilience, continuity, crisis, and incident governance
Governance, Risk & Compliance (GRC) · topic-matchFamily classification, behavior models, YARA, and ATT CK
Malware Analysis & Reverse Engineering · topic-match