Researchers linked multiple campaigns to the StrongPity espionage group after attackers intercepted software downloads and replaced legitimate installers with trojanized packages. In one campaign, users searching for encryption and privacy tools such as WinRAR and TrueCrypt were redirected to malicious sites including ralrab[.]com and true-crypt[.]com, while compromised or abused distributor sites such as winrar[.]be and winrar[.]it helped deliver infected installers. The activity heavily affected users in Italy, Belgium, and Turkey, with additional victims across Europe, North Africa, and the Middle East.
A later operation reused a man-in-the-middle delivery method previously associated with FinFisher, but served Win32/StrongPity2 instead through an unusual HTTP redirect chain consistent with likely ISP-level interception. ESET reported code and operational overlaps with earlier StrongPity malware, including shared obfuscation, similar configuration structures, use of libcurl 7.45, and comparable file-exfiltration behavior. The malware deployed droppers, backdoors, keyloggers, and data stealers, and showed particular interest in systems running tools tied to encrypted communications, including PuTTY, WinSCP, FileZilla, mstsc, and mRemoteNG.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
ESET reported that Win32/StrongPity2 shared code, configuration structure, obfuscation, libcurl usage, and exfiltration behavior with malware attributed to StrongPity. ESET also published indicators of compromise, malicious infrastructure, persistence details, and cleanup guidance.
On 8 October 2017, ESET observed the campaign reappear in one of the previously affected countries, but now distributing Win32/StrongPity2 instead of FinFisher. The operation used the same unusual HTTP redirect structure to send users seeking legitimate software to fake download sites.
ESET telemetry indicated that the previously documented FinFisher campaigns in two countries terminated on 21 September 2017. ESET said those earlier campaigns showed strong indicators of ISP-level involvement.
From mid-July to early September 2016, visitors from tamindir.com were redirected to the attacker-controlled fake TrueCrypt site true-crypt.com. The redirects were focused mainly on systems in Turkey, with some victims in the Netherlands.
The Belgian WinRAR distributor site winrar.be began redirecting visitors to the typosquatted malicious domain ralrab.com, where StrongPity-hosted installers were delivered. Victims redirected through this path were overwhelmingly located in Belgium.
StrongPity began serving trojanized WinRAR executables directly from the Italian distributor site winrar.it. The activity primarily affected users in Italy.
Deployment of poisoned TrueCrypt installers resumed in May 2016 after earlier sightings in Turkey. The campaign used the fake site true-crypt.com to distribute trojanized installers.
In 2016, StrongPity conducted a broader watering-hole and poisoned-installer campaign targeting users seeking encryption-related software such as WinRAR and TrueCrypt. The operation infected more than 1,000 systems, with major impact in Italy, Turkey, Belgium, Algeria, and France.
A third system was recorded receiving the malicious TrueCrypt file in January 2016. The activity was tied to the fake TrueCrypt distribution infrastructure used by StrongPity.
Telemetry recorded a malicious TrueCrypt file associated with StrongPity on two systems in Turkey in December 2015. This is the earliest dated activity described for the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 37 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.