On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users
ID: 312ba789-2e2d-484e-9933-ee44d00ca0d1
STIX ID: report--312ba789-2e2d-484e-9933-ee44d00ca0d1
Threat Score
80/100
Uploaded: 2026-08-19
Published Date: 2016-10-19
Last Modified Date: 2016-10-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
StrongPity APT conducted watering‑hole and poisoned‑installer campaigns in 2015–2016 by compromising localized WinRAR and TrueCrypt distribution pages (examples: winrar.it, winrar.be → ralrab.com, tamindir.com → true-crypt.com) to serve trojanized installers that dropped backdoors, keyloggers and data‑stealers targeting users of encryption‑enabled applications; the report provides IoCs (URLs and filenames), dropped component names, geolocation statistics (hundreds to ~1,000+ infected systems across Italy, Turkey, Belgium and others), and details of the attackers' tactics and C2 behavior.
