Also known as: G0055
NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to overlapping victim and campaign characteristics. (Citation: Microsoft NEODYMIUM Dec 2016) (Citation: Microsoft SIR Vol 21) NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified. (Citation: CyberScoop BlackOasis Oct 2017)
Executive Summary
NEODYMIUM, an activity group linked to espionage activities, has been observed targeting Turkish individuals since at least May 2016. The group shares similarities with PROMETHIUM due to overlapping victimology and campaign characteristics, suggesting a possible connection or shared operational approach. NEODYMIUM's activities may be linked to BlackOasis operations, though no definitive evidence of alias usage has been established. The threat actor employs spear-phishing campaigns using malicious Office documents and demonstrates intermediate sophistication in targeting OSINT platforms.
Goals & Targeting
NEODYMIUM appears to primarily seekEspionage-related intelligence from its targets. This is evident from the targeting of individuals in sectors that likely handle sensitive information, such as defense, government, or OSINT professionals. The group's focus on Turkish victims suggests a potential interest in regional intelligence gathering or geopolitical espionage. NEODYMIUM's strategic goal aligns with other advanced persistent threat (APT) groups seeking to gather critical data for national security or competitive advantage purposes.
Enhanced Description
NEODYMIUM is an espionage-focused activity group that has primarily targeted individuals in Turkey through sophisticated phishing campaigns. The group's operations share notable similarities with PROMETHIUM, another suspected espionage actor, due to overlapping victim characteristics and campaign tactics. NEODYMIUM has been observed using malicious Office documents embedded with macros to deliver payloads, indicating a focus on compromising OSINT platforms. While the group demonstrates intermediate sophistication, its attacks have been effective in targeting defense and government sectors. The actor's association with BlackOasis remains speculative but suggests potential ties to larger state-sponsored or intelligence community operations. NEODYMIUM's primary toolset includes Wingbird, a piece of malware designed for data collection, exfiltration, and persistence. The group has demonstrated a patient and targeted approach, focusing on specific individuals rather than large-scale campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
NEODYMIUM has been active since at least May 2016, with its latest known activities occurring in December 2016. The group's campaigns have focused on Turkish individuals, suggesting a geographically targeted approach. NEODYMIUM's operations demonstrate similarities to PROMETHIUM, including the use of overlapping victim characteristics and malware deployment methods. These parallels raise questions about whether they are distinct groups or part of a larger campaign network. Notable operations include the targeting of OSINT users, likely to compromise sensitive data and disrupt intelligence gathering efforts.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in NEODYMIUM's espionage activities and targeting patterns, based on consistent reporting across multiple sources. However, there is limited clarity regarding the group's precise affiliations with other actors (e.g., BlackOasis or PROMETHIUM). The absence of a definitive link to nation-state sponsorship introduces some uncertainty, though strong indicators suggest state-sponsored activity.
No techniques linked yet.
No observed data linked yet.
0
Techniques
1
Tools
1
Campaigns
52
IOCs
0
Observed Data
0
Tactics