FORENSIA

THREAT_ACTOR · G0056

PROMETHIUM

Also known as: PROMETHIUM, StrongPity

Profile

PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.

MITRE ATT&CK ↗

Techniques

11 ATT&CK techniques attributed to this actor.

Software

2 malware/tools attributed to this actor.

TruvasysStrongPity

Related corpus activity

4,690 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to PROMETHIUM.

IndicatorTypeFamilySevSrc
cve-2026-1969cve851
cve-2026-5815cve851
cve-2021-4045cve851
cve-2021-29441cve851
cve-2025-34037cve851
cve-2007-5693cve851
cve-2025-34054cve854
cve-2023-44976cveransomware852
cve-2026-4368cveransomware851
cve-2021-25646cve851
cve-2025-12057cve851
cve-2025-7852cve851
cve-2016-0638cvephishing851
cve-2021-27137cve858
cve-2025-68670cve852
cve-2016-15047cve854
cve-2014-2321cve851
cve-2026-3102cve853
cve-2020-17456cve851
cve-2025-34117cve851
cve-2017-18377cve851
cve-2013-7471cve851
cve-2026-0740cve851
cve-2026-3844cve851
cve-2025-34085cve851
cve-2025-7443cve851
bd46890121106b43f0c01ab82629400chashcryptojacking802
5115277eabf2d22d49dcef1e155874387d8e783853bd86debf7ff58588aae35dsha256phishing802
7105caa6d4fd8a2c67523d385277528e556ae4f6hash802
248ded4723e9f5da793e5e42d1ba7c2293dd704718f149b84b3b9b818a1f51dbsha256phishing802

Showing the top 30 by severity of 4,690.