PROMETHIUM (StrongPity) is a well-resourced threat group active since 2012, known for trojanized utilities and signed malware deployments.
Analyst brief
PROMETHIUM (StrongPity) is a well-resourced threat group active since at least 2012, often targeting users through trojanized versions of common utilities like WinRAR and TrueCrypt. The group leverages `Drive-by Compromise` and malicious files signed with `Code Signing Certificates` for initial access, deploying Truvasys and StrongPity malware. They achieve persistence primarily via `Registry Run Keys / Startup Folder` and maintain stealth through `Match Legitimate Resource Name or Location`. Defenders should prioritize monitoring for unexpected software installations, especially signed but suspicious binaries, and scrutinizing unusual local account activity.
PROMETHIUM
StrongPityG0056APT-C-41
unknown
PROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation for several years. Truvasys has been involved in several attack campaigns, where it has masqueraded as one of server common computer utilities, including WinUtils, TrueCrypt, WinRAR, or SanDisk. In each of the campaigns, Truvasys malware evolved with additional features—this shows a close relationship between the activity groups behind the campaigns and the developers of the malware.