◇ SIGN IN
← all actors
apt

StrongPity (PROMETHIUM)

activemedium confidence
APT / State-sponsored
PROMETHIUMAPT-C-41StrongPity3
Attribution
Cyber-espionage group with a heavy focus on Turkish and Syrian targets; some reporting suggests possible Turkish-state alignment (assessed, not confirmed)
Origin
Unknown (Turkey-nexus suspected)
First seen
2016
Last active
2023-2024
Motivation
Espionage
Confidence
medium
MENA targeting
Syria, Turkey (Kurdish-population-focused)
Sectors
Individuals/general users via watering holes, ISP-level traffic
MITRE ATT&CK
Why it mattersState-sponsored / APT actor, medium confidence, documented targeting Syria, Turkey (Kurdish-population-focused) (Individuals/general users via watering holes, ISP-level traffic sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

StrongPity (MITRE PROMETHIUM, G0056) is a long-running espionage actor best known for distributing Trojanized versions of popular software and, more recently, Trojanized Android apps, with a persistent focus on Turkey, Syria and the Kurdish community.

History

PROMETHIUM/StrongPity has been active since at least 2012 and was first widely publicized in 2016 after watering-hole and Trojanized-installer campaigns (notably weaponized WinRAR and TrueCrypt) targeting users in Italy, Belgium, Turkey and Syria. MITRE tracks it as G0056 and notes overlaps with the NEODYMIUM cluster.

The group's signature technique is supply-style tampering: it repackages legitimate software (Notepad++, WinRAR, TrueCrypt, Telegram and others) with backdoor code and delivers it via fake distribution sites and watering holes, often abusing code-signing and search-order abuse for persistence. Bitdefender and Talos have documented a modular StrongPity toolkit with document/file exfiltration and self-updating components.

MENA relevance is strong: multiple campaigns have deliberately targeted Syria, Turkey and the Kurdish community, including watering-hole attacks aimed at Kurdish victims and a Trojanized Telegram app (2023). Reported victim geographies have also expanded to Colombia, India, Canada and Vietnam.

Attribution is unresolved. Some analysts infer a Turkey-aligned interest set from repeated Kurdish and Syrian targeting, but this is an assessment (medium confidence); the underlying espionage activity is high confidence given years of vendor reporting. No high-profile new StrongPity campaign has been publicly disclosed in 2025-2026, so status is 'active' based on recent-years persistence but with a stale last-confirmed date.

Notable campaigns

2016
Trojanized WinRAR/TrueCrypt watering holes
Weaponized installers of popular encryption/archive tools delivered via fake sites to victims in Italy, Belgium, Turkey and Syria.
2020
StrongPity3 / Kurdish watering holes
Talos documented an expanded, modular toolkit and watering-hole attacks focused on the Kurdish community and Syrian/Turkish targets.
2023
Trojanized Telegram (Android)
A fake site distributed a backdoored Telegram (Shagle-themed) app to compromise Android users.