Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware StrongPity

StrongPity

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

StrongPity is a Windows information‑stealing trojan used by the Promethium group that harvests credentials from browsers and other applications, exfiltrates data via HTTP/S and disables security software. It also monitors clipboard activity, captures screenshots, and injects malicious code into sites for phishing attacks. The malware’s ability to update itself makes detection and mitigation harder, requiring proactive endpoint protection.

Enhanced Description

StrongPity is a Windows‑based information‑stealing malware that has been linked to the Promethium group as early as June 2020, according to Bitdefender and Cisco Talos reports. The payload operates primarily by harvesting usernames and passwords from browsers, local credential stores, and other applications – effectively acting as a banking trojan. Once compromised, StrongPity packages collected data and exfiltrates it to remote command‑and‑control (C2) servers over HTTP/HTTPS, leveraging common web protocols to blend in with legitimate traffic. The malware also includes auxiliary routines that monitor clipboard activity for credentials, injects malicious code into webpages for credential harvesting, and can disable Windows Defender or other security software by modifying registry keys. In some samples it has shown the ability to capture screenshots and log keystrokes, further expanding its data‑steal capabilities. StrongPity's architecture allows attackers to update malicious modules, enabling them to add new features such as phishing form injection or additional credential collection vectors. Because banking trojans like StrongPity typically target a wide range of financial institutions and e‑commerce sites, the threat persists across diverse sectors that store sensitive user information. Overall, StrongPity poses an ongoing risk for organizations with exposed web services, compromised endpoints, or weak patch management practices, as its automated updates make it difficult to remain resilient without proactive detection.

Key Capabilities

  • Collects usernames and passwords from browsers and local credential stores
  • Monitors clipboard for credential theft
  • Captures screenshots and logs keystrokes
  • Disables or evades antivirus/endpoint protection via registry modifications
  • Exfiltrates stolen data to remote C2 servers over HTTP/S
  • Injects malicious code into webpages for phishing

ATT&CK Techniques

T1059.003
T1071.001
T1064
T1110
T1145
T1558.001

Recommended Actions

  • Implement network segmentation to block outbound traffic to known StrongPity C2 domains and IP ranges
  • Deploy endpoint detection & response (EDR) solutions that flag credential theft, clipboard monitoring, and registry tampering
  • Keep Windows OS and all applications up‑to‑date with the latest security patches
  • Regularly update antivirus signatures for StrongPity and related variants
  • Use application whitelisting to prevent unauthorized runtime of unknown executables

Suggested Tags

banking trojan
information stealer
credential theft
Promethium
Windows malware

Confidence Assessment

The information is drawn from two reputable vendor alerts but lacks detailed technical reports, sample analysis data, or precise indicator lists. Confidence in the core capabilities (credential theft, web injection) remains high; however, gaps exist regarding persistence mechanisms, encryption methods for exfiltration, and full malware architecture, which limits a comprehensive assessment.

Description

StrongPity is an information stealing malware used by PROMETHIUM.(Citation: Bitdefender StrongPity June 2020)(Citation: Talos Promethium June 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.