Also known as: StrongPity, G0056, APT-C-41
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.(Citation: Microsoft NEODYMIUM Dec 2016)(Citation: Microsoft SIR Vol 21)(Citation: Talos Promethium June 2020)
Executive Summary
PROMETHIUM is an espionage‑focused activity group active since at least 2012, with a documented emphasis on Turkish targets but operating globally. The group exhibits operational overlap with the NEODYMIUM activity set, suggesting shared tooling or tradecraft. Its campaigns leverage classic credential‑theft and lateral‑movement techniques to gain persistent access to high‑value networks.
Goals & Targeting
PROMETHIUM’s strategic objective appears to be the collection of political, military, and economic intelligence from Turkish and allied entities. By compromising ministries, defense contractors, and critical infrastructure providers, the group can harvest classified documents, network diagrams, and credential databases that support nation‑state intelligence requirements. The typical victims are high‑value organizations with access to sensitive state information, making the group’s targeting profile highly selective and mission‑oriented rather than financially motivated.
Enhanced Description
PROMETHIUM is an activity group that has been conducting cyber‑espionage operations since at least 2012. Publicly available reports indicate that the group conducts campaigns worldwide, yet it shows a pronounced focus on entities located in Turkey, including government ministries, defense contractors, and critical infrastructure operators. The group’s operational patterns and victimology closely mirror those of the NEODYMIUM activity set, leading analysts to suspect shared tooling, infrastructure, or even personnel. Both groups have been observed employing similar phishing lures, custom malware families, and post‑exploitation workflows, which complicates attribution but underscores a consistent threat model aimed at intelligence collection. Technical analyses from Microsoft and Talos reveal that PROMETHIUM leverages a blend of off‑the‑shelf post‑exploitation frameworks (e.g., Cobalt Strike) and bespoke back‑doors designed to evade detection. The group’s malware often incorporates PowerShell‑based loaders, credential‑dumping utilities, and data‑exfiltration modules that communicate over encrypted HTTP/HTTPS channels. While the precise sponsoring entity remains unidentified, the sustained focus on Turkish strategic sectors and the sophistication of the tooling suggest a state‑aligned actor or a well‑funded cyber‑espionage outfit. Continued monitoring of the group’s TTPs is essential for organizations operating in the affected sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since its first documented activity in 2012, PROMETHIUM has run a series of low‑and‑high‑tempo campaigns that align with geopolitical events affecting Turkey. Campaigns often spike around regional elections, military procurements, or energy sector negotiations, indicating a strategic alignment with intelligence‑gathering cycles. The group typically stages its infrastructure on bullet‑proof hosting services, re‑uses domain aliases across campaigns, and employs fast‑flux DNS to obscure C2 endpoints. Notable operations include a 2018 intrusion into a Turkish defense contractor that resulted in the exfiltration of prototype schematics, and a 2020 supply‑chain compromise of a software vendor serving Turkish telecom operators.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the overall activity profile of PROMETHIUM is moderate to high, supported by multiple vendor reports (Microsoft, Talos) that document overlapping TTPs with NEODYMIUM. However, gaps remain regarding the group’s exact sponsoring nation‑state, the full inventory of custom malware families, and precise timeline details for many campaigns. Continued collection of technical artefacts and attribution research is required to close these gaps.
No observed data linked yet.
11
Techniques
2
Tools
2
Campaigns
73
IOCs
0
Observed Data
6
Tactics