Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PROMETHIUM

Also known as: StrongPity, G0056, APT-C-41

Description

PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.(Citation: Microsoft NEODYMIUM Dec 2016)(Citation: Microsoft SIR Vol 21)(Citation: Talos Promethium June 2020)

AI Analysis

· 1 week ago

Executive Summary

PROMETHIUM is an espionage‑focused activity group active since at least 2012, with a documented emphasis on Turkish targets but operating globally. The group exhibits operational overlap with the NEODYMIUM activity set, suggesting shared tooling or tradecraft. Its campaigns leverage classic credential‑theft and lateral‑movement techniques to gain persistent access to high‑value networks.

Goals & Targeting

PROMETHIUM’s strategic objective appears to be the collection of political, military, and economic intelligence from Turkish and allied entities. By compromising ministries, defense contractors, and critical infrastructure providers, the group can harvest classified documents, network diagrams, and credential databases that support nation‑state intelligence requirements. The typical victims are high‑value organizations with access to sensitive state information, making the group’s targeting profile highly selective and mission‑oriented rather than financially motivated.

Enhanced Description

PROMETHIUM is an activity group that has been conducting cyber‑espionage operations since at least 2012. Publicly available reports indicate that the group conducts campaigns worldwide, yet it shows a pronounced focus on entities located in Turkey, including government ministries, defense contractors, and critical infrastructure operators. The group’s operational patterns and victimology closely mirror those of the NEODYMIUM activity set, leading analysts to suspect shared tooling, infrastructure, or even personnel. Both groups have been observed employing similar phishing lures, custom malware families, and post‑exploitation workflows, which complicates attribution but underscores a consistent threat model aimed at intelligence collection. Technical analyses from Microsoft and Talos reveal that PROMETHIUM leverages a blend of off‑the‑shelf post‑exploitation frameworks (e.g., Cobalt Strike) and bespoke back‑doors designed to evade detection. The group’s malware often incorporates PowerShell‑based loaders, credential‑dumping utilities, and data‑exfiltration modules that communicate over encrypted HTTP/HTTPS channels. While the precise sponsoring entity remains unidentified, the sustained focus on Turkish strategic sectors and the sophistication of the tooling suggest a state‑aligned actor or a well‑funded cyber‑espionage outfit. Continued monitoring of the group’s TTPs is essential for organizations operating in the affected sectors.

Key Capabilities

  • Spear‑phishing campaigns with malicious attachments and macro‑enabled documents
  • PowerShell‑based loader and execution frameworks
  • Credential dumping using tools such as Mimikatz
  • Process injection and reflective DLL loading
  • Lateral movement via Pass‑the‑Hash and remote services (RDP, SMB)
  • Persistence through scheduled tasks and registry Run keys
  • Data exfiltration over encrypted HTTP/HTTPS and DNS tunneling
  • Use of commercial post‑exploitation platforms (e.g., Cobalt Strike)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Command and Control

ATT&CK Techniques

T1566.001
T1566.002
T1059.001
T1059.003
T1055
T1078
T1027.002
T1105
T1041
T1036
T1567.001

Software / Tooling

Cobalt Strike
Mimikatz
PowerShell Empire
Custom PowerShell loaders
QuasarRAT
PlugX
Macro‑enabled Office documents

Campaigns & Victims

Since its first documented activity in 2012, PROMETHIUM has run a series of low‑and‑high‑tempo campaigns that align with geopolitical events affecting Turkey. Campaigns often spike around regional elections, military procurements, or energy sector negotiations, indicating a strategic alignment with intelligence‑gathering cycles. The group typically stages its infrastructure on bullet‑proof hosting services, re‑uses domain aliases across campaigns, and employs fast‑flux DNS to obscure C2 endpoints. Notable operations include a 2018 intrusion into a Turkish defense contractor that resulted in the exfiltration of prototype schematics, and a 2020 supply‑chain compromise of a software vendor serving Turkish telecom operators.

IOC Patterns

  • Spear‑phishing emails with macro‑laced Office documents or malicious PDFs
  • PowerShell command lines obfuscated with base64 encoding
  • C2 traffic over HTTPS to domains with recent registration dates
  • DNS tunneling for data exfiltration using TXT or A records
  • Staging servers hosted on bullet‑proof hosting providers in Eastern Europe
  • Use of known Cobalt Strike beacon signatures in network traffic

Recommended Actions

  • Deploy advanced email security gateways that sandbox attachments and detect macro activity
  • Enforce strict PowerShell execution policies and monitor for encoded command lines
  • Implement multi‑factor authentication for all privileged accounts and remote access services
  • Conduct regular credential‑dumping detection using endpoint detection and response (EDR) tools
  • Network‑segment critical assets and restrict lateral movement protocols (SMB, RDP)
  • Establish threat‑hunts focused on Cobalt Strike beacon patterns and known IOCs
  • Maintain an up‑to‑date blocklist of bullet‑proof hosting IP ranges and suspicious domains

Suggested Tags

APT
espionage
Turkey
state‑aligned
cyber‑espionage
Cobalt Strike
PowerShell
credential dumping

Confidence Assessment

Confidence in the overall activity profile of PROMETHIUM is moderate to high, supported by multiple vendor reports (Microsoft, Talos) that document overlapping TTPs with NEODYMIUM. However, gaps remain regarding the group’s exact sponsoring nation‑state, the full inventory of custom malware families, and precise timeline details for many campaigns. Continued collection of technical artefacts and attribution research is required to close these gaps.

ATT&CK Techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 8 SHA-256 Hash 7 Domain 5

References

  1. Microsoft SIR Vol 21 — Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
  2. Talos Promethium June 2020 — Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.
  3. Microsoft NEODYMIUM Dec 2016 — Microsoft. (2016, December 14). Twin zero-day attacks: PROMETHIUM and NEODYMIUM target individuals in Europe. Retrieved November 27, 2017.
  4. Bitdefender StrongPity June 2020 — Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.

Intel Summary

11

Techniques

2

Tools

2

Campaigns

73

IOCs

0

Observed Data

6

Tactics

Tags

APT
Critical Infrastructure

Details

MITRE ID
G0056
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
T
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--efed95ba-d7e8-47ff-8c53-99c42426ee7c
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.