Cyber-espionage group with a heavy focus on Turkish and Syrian targets; some reporting suggests possible Turkish-state alignment (assessed, not confirmed)
Origin
Unknown (Turkey-nexus suspected)
First seen
2016
Last active
2023-2024
Motivation
Espionage
Attribution confidence
medium
MENA targeting
Syria, Turkey (Kurdish-population-focused)
Sectors
Individuals/general users via watering holes, ISP-level traffic
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.(Citation: Talos Promethium June
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has used watering hole attacks to deliver malicious versions of legitimate installers.(Citation: Bitdefender StrongPity June 2020)
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has created new services and modified existing services for persistence.(Citation: Bitdefender StrongPity June 2020)
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has created self-signed digital certificates for use in HTTPS C2 traffic.(Citation: Talos Promethium June 2020)
→Masquerade Task or ServicetechniqueATT&CK mapping
→Code SigningtechniqueATT&CK mapping
→Registry Run Keys / Startup FoldertechniqueATT&CK mapping
→Digital CertificatestechniqueATT&CK mapping
→Malicious FiletechniqueATT&CK mapping
→Port KnockingtechniqueATT&CK mapping
→Match Legitimate Resource Name or LocationtechniqueATT&CK mapping
→Drive-by CompromisetechniqueATT&CK mapping
→Local AccountstechniqueATT&CK mapping
Code Signing Certificates
Resource Development
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has created self-signed certificates to sign malicious installers.(Citation: Bitdefender StrongPity June 2020)
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has disguised malicious installer files by bundling them with legitimate software installers.(Citation: Talos Promethium June 2020)(Citation: Bitdefender StrongPity June 2020)
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports.(Citation: Bitdefender StrongPity June 2020)
[PROMETHIUM](https://attack.mitre.org/groups/G0056) has named services to appear legitimate.(Citation: Talos Promethium June 2020)(Citation: Bitdefender StrongPity June 2020)
Associated software
2 linked · 2 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 2
Sourced from MITRE ATT&CK's own uses relationships for this group.
MITRE ATT&CK campaigns attributed to this actor's group (G0056) — named, time-bounded operations with their own technique sets. Sourced from MITRE ATT&CK.
Regional co-occurrence is association, not prediction. These techniques appeared alongside StrongPity (PROMETHIUM)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1036partialAdaptive Application Control IntegrationT1036.005partialAdaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdaptive Application Control IntegrationT1553minimalAdaptive Application Control IntegrationT1553.002partialApp GovernanceT1078significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1189partialDefender for Cloud AppsT1078partialDefender for Cloud AppsT1189partialMicrosoft Defender for IdentityT1543minimalMicrosoft Defender for IdentityT1543.003
respond · 5 techniques
Automated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1189significantAutomated Investigation and ResponseT1204.002significantIncident ResponseT1078minimalQuarantine PoliciesT1036significantQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantSafe AttachmentsT1204significantSafe AttachmentsT1204.002significantATT&CK Simulation TrainingT1189partialATT&CK Simulation TrainingT1204partialATT&CK Simulation TrainingT1204.002partialZero Hour Auto PurgeT1036significant
Countermeasures · D3FEND
Defensive techniques that counter StrongPity (PROMETHIUM)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.