logo

Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-StrongPity_APT-creat4574-en_EN:Bitdefender-PR-Whitepaper-StrongPity_APT-creat4574-en_EN.indd

ID: b8c10d38-cf29-4f1e-9c65-6cc70663866b

STIX ID: report--b8c10d38-cf29-4f1e-9c65-6cc70663866b

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2020-06-15

Last Modified Date: 2020-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender analysis of the StrongPity (Promethium) APT documents a targeted watering‑hole/supply‑chain campaign that serves Trojanized legitimate installers to selected IP ranges (primarily in Turkey and northern Syria). The actor uses a signed custom dropper that unpacks multiple encrypted components (launcher, persistence service, file searcher and exfiltration module), a three‑tier C2/proxy infrastructure to hide terminals, HTTPS over nonstandard ports, and bespoke file encryption (.sft) for exfiltration; the report includes infrastructure details, timeline, and a long list of compile timestamps and sample hashes.