logo

PROMETHIUM__2020__Newly_identified_StrongPity_operations_AT_T_Alien_Labs.pdf

ID: 51e49c06-c597-4f31-a151-544fb904e65e

STIX ID: report--51e49c06-c597-4f31-a151-544fb904e65e

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2020-06-30

Last Modified Date: 2020-06-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Alien Labs (AT&T Cybersecurity) reports newly identified StrongPity activity: malicious, trojanized installers of trusted software (WinBox, WinRAR, Internet Download Manager) that deploy StrongPity spyware and provide persistent remote access. The report includes technical details on payload behavior (dropped executable, SSL C2 communications), compilation-time clustering, C2 domains/URIs, PE certificate metadata and numerous SHA256 hashes, and assesses the campaign as ongoing from late 2018 into mid-2019 with targeting of technically oriented users.