PROMETHIUM is a threat actor associated with the StrongPity spyware family and mobile surveillance activity tracked as campaign C0033. In this activity, PROMETHIUM used StrongPity to collect victim contact lists, call logs, and device profiling data including SIM-related information, and to communicate with command-and-control infrastructure over HTTPS. The observed behavior is consistent with mobile spyware operations focused on intelligence collection and post-compromise surveillance rather than disruptive or ransomware activity. PROMETHIUM is widely associated with StrongPity operations and is known for using that malware to harvest sensitive data from compromised devices while maintaining remote operator control through encrypted application-layer communications.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated with use of StrongPity to collect device information from mobile devices.
Named activity cluster associated in the content with PROMETHIUM using StrongPity over HTTPS for command-and-control.
Named activity cluster in which PROMETHIUM used StrongPity to collect call logs.
Named activity cluster referenced as the campaign context in which PROMETHIUM used StrongPity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.