logo

PROMETHIUM__2016__On_the_StrongPity_Waterhole_Attacks_-_Securelist.pdf

ID: 9bca35e2-4e20-4b72-9094-018b24774939

STIX ID: report--9bca35e2-4e20-4b72-9094-018b24774939

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2016-10-14

Last Modified Date: 2016-10-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky report details the StrongPity APT’s summer 2016 watering‑hole and poisoned‑installer campaign that targeted users of encryption tools (notably WinRAR and TrueCrypt) by compromising localized distributor and software‑sharing sites (e.g., winrar.it, winrar.be -> ralrab.com, tamindir.com -> true-crypt.com). The attackers delivered signed droppers that installed backdoors, keyloggers and data‑stealers, focused infections in Italy, Belgium and Turkey (over 1,000 systems overall), and published multiple IOCs (malicious URLs and filenames) while recommending stronger distribution integrity checks and code signing.