PROMETHIUM, also referred to as StrongPity, Magenta Dust, and SmallPity, is a threat actor associated in the provided content with both Windows and Android malware activity. The content explicitly links an Android malware sample posted on the Syrian e-Gov website to the StrongPity threat group and describes StrongPity as actively developing Android backdoors. In the Windows context, PROMETHIUM has established persistence using Registry Run keys and by creating new services or modifying existing Windows services. The group has also attempted to get users to execute compromised installation files for legitimate software, including compression applications, security software, browsers, file recovery applications, and other utilities, and has disguised malicious installer files by bundling them with legitimate software installers. In Android activity tracked as C0033, PROMETHIUM used StrongPity to communicate with command-and-control servers over HTTPS and to exfiltrate data over HTTPS. The malware collected SMS messages, call logs, contact lists, and device information including SIM serial number. The broader Android reporting in the content states that StrongPity used repackaged applications, fake applications, and compromised websites to lure victims into sideloading malicious APKs from unknown sources. The Android tooling is described as modular, with collected data written to a local SQLite database in a newer version, support for downloading additional modules, screen event-based service start behavior, and the ability to execute the "su" command on rooted devices to silently grant permissions. The content also notes infrastructure overlaps with domains such as upn-sec3-msd[.]com, networktopologymaps[.]com, hostoperationsystems[.]com, and upeg-system-app[.]com. A similar but smaller example could be the Promethium group is also mentioned in the content, but no additional high-confidence attribution beyond the aliases and behaviors above is provided.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor for exploitation activity related to abuse of the Windows Cloud Files API / cldapi.dll detection.
Listed as a threat actor associated with exploitation and privilege-escalation detection coverage for Windows admin password changes by non-admin users.
Listed as a threat actor associated with exploitation for privilege escalation and Windows service persistence/installation in the detection annotations.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.