PROMETHIUM__2020__Newly_identified_StrongPity_operations_AT_T_Alien_Labs.pdf
ID: 51e49c06-c597-4f31-a151-544fb904e65e
STIX ID: report--51e49c06-c597-4f31-a151-544fb904e65e
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2020-06-30
Last Modified Date: 2020-06-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Alien Labs (AT&T Cybersecurity) reports newly identified StrongPity activity: malicious, trojanized installers of trusted software (WinBox, WinRAR, Internet Download Manager) that deploy StrongPity spyware and provide persistent remote access. The report includes technical details on payload behavior (dropped executable, SSL C2 communications), compilation-time clustering, C2 domains/URIs, PE certificate metadata and numerous SHA256 hashes, and assesses the campaign as ongoing from late 2018 into mid-2019 with targeting of technically oriented users.
