StrongPity is a Turkey-based threat actor known for highly targeted espionage operations centered on the StrongPity backdoor. The group has also deployed Android malware and has maintained activity over multiple years, including continued use of its namesake backdoor during 2021. Its operations are characterized by selective targeting and malware-enabled surveillance rather than broad disruptive or financially motivated campaigns. StrongPity is also tracked as Teal Dev 2. High-confidence reporting supports its use of custom backdoor tooling and mobile malware in targeted intrusions, consistent with an espionage-oriented collection mission.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.