logo

On the StrongPity Waterhole Attacks Targeting Italian and Belgian Encryption Users

ID: 312ba789-2e2d-484e-9933-ee44d00ca0d1

STIX ID: report--312ba789-2e2d-484e-9933-ee44d00ca0d1

Threat Score

80/100

Uploaded: 2026-08-19

Published Date: 2016-10-19

Last Modified Date: 2016-10-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
StrongPity APT conducted watering‑hole and poisoned‑installer campaigns in 2015–2016 by compromising localized WinRAR and TrueCrypt distribution pages (examples: winrar.it, winrar.be → ralrab.com, tamindir.com → true-crypt.com) to serve trojanized installers that dropped backdoors, keyloggers and data‑stealers targeting users of encryption‑enabled applications; the report provides IoCs (URLs and filenames), dropped component names, geolocation statistics (hundreds to ~1,000+ infected systems across Italy, Turkey, Belgium and others), and details of the attackers' tactics and C2 behavior.