PROMETHIUM__2016__On_the_StrongPity_Waterhole_Attacks_-_Securelist.pdf
ID: 9bca35e2-4e20-4b72-9094-018b24774939
STIX ID: report--9bca35e2-4e20-4b72-9094-018b24774939
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2016-10-14
Last Modified Date: 2016-10-14
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky report details the StrongPity APT’s summer 2016 watering‑hole and poisoned‑installer campaign that targeted users of encryption tools (notably WinRAR and TrueCrypt) by compromising localized distributor and software‑sharing sites (e.g., winrar.it, winrar.be -> ralrab.com, tamindir.com -> true-crypt.com). The attackers delivered signed droppers that installed backdoors, keyloggers and data‑stealers, focused infections in Italy, Belgium and Turkey (over 1,000 systems overall), and published multiple IOCs (malicious URLs and filenames) while recommending stronger distribution integrity checks and code signing.
