THREAT_ACTOR · G0056
PROMETHIUM
Also known as: PROMETHIUM, StrongPity
Profile
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.
MITRE ATT&CK ↗Techniques
11 ATT&CK techniques attributed to this actor.
T1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1078.003 Local AccountsT1189 Drive-by CompromiseT1204.002 Malicious FileT1205.001 Port KnockingT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1553.002 Code SigningT1587.002 Code Signing CertificatesT1587.003 Digital Certificates
Software
2 malware/tools attributed to this actor.
TruvasysStrongPity
Related corpus activity
4,690 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to PROMETHIUM.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2026-5815 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-34037 | cve | — | 85 | 1 |
| cve-2007-5693 | cve | — | 85 | 1 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2016-0638 | cve | phishing | 85 | 1 |
| cve-2021-27137 | cve | — | 85 | 8 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2025-34085 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| 7105caa6d4fd8a2c67523d385277528e556ae4f6 | hash | — | 80 | 2 |
| 5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35d | sha256 | phishing | 80 | 2 |
| c2eb1033bc01ab0fd732a7ba4967be02c0690bf0 | hash | — | 80 | 2 |
| 248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51db | sha256 | phishing | 80 | 2 |
Showing the top 30 by severity of 4,690.