StrongPity (MITRE PROMETHIUM, G0056) is a long-running espionage actor best known for distributing Trojanized versions of popular software and, more recently, Trojanized Android apps, with a persistent focus on Turkey, Syria and the Kurdish community.
PROMETHIUM/StrongPity has been active since at least 2012 and was first widely publicized in 2016 after watering-hole and Trojanized-installer campaigns (notably weaponized WinRAR and TrueCrypt) targeting users in Italy, Belgium, Turkey and Syria. MITRE tracks it as G0056 and notes overlaps with the NEODYMIUM cluster.
The group's signature technique is supply-style tampering: it repackages legitimate software (Notepad++, WinRAR, TrueCrypt, Telegram and others) with backdoor code and delivers it via fake distribution sites and watering holes, often abusing code-signing and search-order abuse for persistence. Bitdefender and Talos have documented a modular StrongPity toolkit with document/file exfiltration and self-updating components.
MENA relevance is strong: multiple campaigns have deliberately targeted Syria, Turkey and the Kurdish community, including watering-hole attacks aimed at Kurdish victims and a Trojanized Telegram app (2023). Reported victim geographies have also expanded to Colombia, India, Canada and Vietnam.
Attribution is unresolved. Some analysts infer a Turkey-aligned interest set from repeated Kurdish and Syrian targeting, but this is an assessment (medium confidence); the underlying espionage activity is high confidence given years of vendor reporting. No high-profile new StrongPity campaign has been publicly disclosed in 2025-2026, so status is 'active' based on recent-years persistence but with a stale last-confirmed date.