Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors NEODYMIUM

Also known as: G0055

Description

NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to overlapping victim and campaign characteristics. (Citation: Microsoft NEODYMIUM Dec 2016) (Citation: Microsoft SIR Vol 21) NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified. (Citation: CyberScoop BlackOasis Oct 2017)

AI Analysis

· 1 week ago

Executive Summary

NEODYMIUM, an activity group linked to espionage activities, has been observed targeting Turkish individuals since at least May 2016. The group shares similarities with PROMETHIUM due to overlapping victimology and campaign characteristics, suggesting a possible connection or shared operational approach. NEODYMIUM's activities may be linked to BlackOasis operations, though no definitive evidence of alias usage has been established. The threat actor employs spear-phishing campaigns using malicious Office documents and demonstrates intermediate sophistication in targeting OSINT platforms.

Goals & Targeting

NEODYMIUM appears to primarily seekEspionage-related intelligence from its targets. This is evident from the targeting of individuals in sectors that likely handle sensitive information, such as defense, government, or OSINT professionals. The group's focus on Turkish victims suggests a potential interest in regional intelligence gathering or geopolitical espionage. NEODYMIUM's strategic goal aligns with other advanced persistent threat (APT) groups seeking to gather critical data for national security or competitive advantage purposes.

Enhanced Description

NEODYMIUM is an espionage-focused activity group that has primarily targeted individuals in Turkey through sophisticated phishing campaigns. The group's operations share notable similarities with PROMETHIUM, another suspected espionage actor, due to overlapping victim characteristics and campaign tactics. NEODYMIUM has been observed using malicious Office documents embedded with macros to deliver payloads, indicating a focus on compromising OSINT platforms. While the group demonstrates intermediate sophistication, its attacks have been effective in targeting defense and government sectors. The actor's association with BlackOasis remains speculative but suggests potential ties to larger state-sponsored or intelligence community operations. NEODYMIUM's primary toolset includes Wingbird, a piece of malware designed for data collection, exfiltration, and persistence. The group has demonstrated a patient and targeted approach, focusing on specific individuals rather than large-scale campaigns.

Key Capabilities

  • Spear-phishing campaigns using malicious Office documents
  • Use of malware (e.g., Wingbird) for data collection and exfiltration
  • Focus on OSINT platforms as infection vectors
  • Intermediate-level operational sophistication

MITRE ATT&CK Tactics

Espionage
Disruption
Collection

ATT&CK Techniques

T1059.003
T1238.001
T1078
T125
T1566.001

Software / Tooling

Wingbird

Campaigns & Victims

NEODYMIUM has been active since at least May 2016, with its latest known activities occurring in December 2016. The group's campaigns have focused on Turkish individuals, suggesting a geographically targeted approach. NEODYMIUM's operations demonstrate similarities to PROMETHIUM, including the use of overlapping victim characteristics and malware deployment methods. These parallels raise questions about whether they are distinct groups or part of a larger campaign network. Notable operations include the targeting of OSINT users, likely to compromise sensitive data and disrupt intelligence gathering efforts.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • Use of malicious hashes for payload delivery
  • C2 communication via encoded protocols in files

Recommended Actions

  • Implement strict monitoring of spear-phishing attempts using email security solutions
  • Conduct regular user training on phishing awareness and OSINT platform hygiene
  • Deploy endpoint detection and response (EDR) tools to identify malicious activity
  • Analyze file hashes against known NEODYMIUM IOCs for potential lateral movement

Suggested Tags

APT
espionage
osint-targeting
russia-linked
malware-dropper

Confidence Assessment

High confidence in NEODYMIUM's espionage activities and targeting patterns, based on consistent reporting across multiple sources. However, there is limited clarity regarding the group's precise affiliations with other actors (e.g., BlackOasis or PROMETHIUM). The absence of a definitive link to nation-state sponsorship introduces some uncertainty, though strong indicators suggest state-sponsored activity.

ATT&CK Techniques

No techniques linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

MD5 Hash 8 SHA-256 Hash 7 Domain 5

References

  1. Microsoft NEODYMIUM Dec 2016 — Microsoft. (2016, December 14). Twin zero-day attacks: PROMETHIUM and NEODYMIUM target individuals in Europe. Retrieved November 27, 2017.
  2. Microsoft SIR Vol 21 — Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
  3. CyberScoop BlackOasis Oct 2017 — Bing, C. (2017, October 16). Middle Eastern hacking group is using FinFisher malware to conduct international espionage. Retrieved February 15, 2018.

Intel Summary

0

Techniques

1

Tools

1

Campaigns

52

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
espionage
osint-targeting
russia-linked
malware-dropper

Details

MITRE ID
G0055
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--025bdaa9-897d-4bad-afa6-013ba5734653
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.