Executive Summary
StrongPity is a Windows information‑stealing trojan used by the Promethium group that harvests credentials from browsers and other applications, exfiltrates data via HTTP/S and disables security software. It also monitors clipboard activity, captures screenshots, and injects malicious code into sites for phishing attacks. The malware’s ability to update itself makes detection and mitigation harder, requiring proactive endpoint protection.
Enhanced Description
StrongPity is a Windows‑based information‑stealing malware that has been linked to the Promethium group as early as June 2020, according to Bitdefender and Cisco Talos reports. The payload operates primarily by harvesting usernames and passwords from browsers, local credential stores, and other applications – effectively acting as a banking trojan. Once compromised, StrongPity packages collected data and exfiltrates it to remote command‑and‑control (C2) servers over HTTP/HTTPS, leveraging common web protocols to blend in with legitimate traffic. The malware also includes auxiliary routines that monitor clipboard activity for credentials, injects malicious code into webpages for credential harvesting, and can disable Windows Defender or other security software by modifying registry keys. In some samples it has shown the ability to capture screenshots and log keystrokes, further expanding its data‑steal capabilities. StrongPity's architecture allows attackers to update malicious modules, enabling them to add new features such as phishing form injection or additional credential collection vectors. Because banking trojans like StrongPity typically target a wide range of financial institutions and e‑commerce sites, the threat persists across diverse sectors that store sensitive user information. Overall, StrongPity poses an ongoing risk for organizations with exposed web services, compromised endpoints, or weak patch management practices, as its automated updates make it difficult to remain resilient without proactive detection.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The information is drawn from two reputable vendor alerts but lacks detailed technical reports, sample analysis data, or precise indicator lists. Confidence in the core capabilities (credential theft, web injection) remains high; however, gaps exist regarding persistence mechanisms, encryption methods for exfiltration, and full malware architecture, which limits a comprehensive assessment.
StrongPity is an information stealing malware used by PROMETHIUM.(Citation: Bitdefender StrongPity June 2020)(Citation: Talos Promethium June 2020)