🇹🇷

PROMETHIUM

APT Group Information theft and espionage 6 zero-day CVEs ETDA ✓

Also Known As 2 names

G0056 StrongPity

Target Countries 19

Countries highlighted in red

Belgium Canada Colombia Germany Algeria Egypt France India Iraq Italy Morocco Netherlands Poland Senegal Tunisia Turkey United States Vietnam South Africa

Sectors Targeted

No targeted sector recorded

Details

Origin 🇹🇷 TR
Last Updated 01 Jun 2022

MITRE ATT&CK 138

T1001 - Data Obfuscation T1003 T1005 T1007 T1008 T1011 T1012 T1016 T1021 T1025 T1027 - Obfuscated Files or Information T1033 T1036 T1036.004 T1036.005 T1038 - DLL Search Order Hijacking T1041 T1047 T1048 - Exfiltration Over Alternative Protocol T1049 T1053 - Scheduled Task/Job T1053.001 - At (Linux) T1053.002 - At (Windows) T1053.003 - Cron T1053.006 - Systemd Timers T1053.007 - Container Orchestration Job T1055 - Process Injection T1055.001 - Dynamic-link Library Injection T1055.002 - Portable Executable Injection T1055.003 - Thread Execution Hijacking T1055.004 - Asynchronous Procedure Call T1055.008 - Ptrace System Calls T1056 T1057 T1059 T1059.001 T1059.003 T1060 T1068 T1070 T1071 T1071.001 T1078 T1078.003 T1081 T1082 T1083 T1085 T1087 T1090 T1095 T1102 T1105 T1106 T1110 T1112 T1113 T1114 T1114.001 T1115 T1119 T1120 T1123 T1124 T1127 T1130 T1132 T1133 T1134 T1136 T1137 T1140 - Deobfuscate/Decode Files or Information T1170 T1176 T1187 T1189 T1190 T1199 T1204 - User Execution T1204.002 T1205 T1205.001 T1217 T1218 - Signed Binary Proxy Execution T1398 T1406 T1407 T1417 T1418 T1420 T1422 T1426 T1429 T1430 T1437 T1485 T1486 T1489 T1490 - Inhibit System Recovery T1496 T1497 T1497.003 T1498 - Network Denial of Service T1503 T1513 T1517 T1518 T1521 T1529 T1530 T1531 T1532 T1539 T1543 - Create or Modify System Process T1543.003 T1547 T1547.001 T1550 T1552 T1553 - Subvert Trust Controls T1553.002 T1555 T1557 T1560 T1561 T1562 - Impair Defenses T1562.001 T1565 T1566 - Phishing T1566.001 T1571 T1573 T1583 T1587 T1587.002 T1587.003 T1590 T1595