ATT&CKGroupsPROMETHIUM

PROMETHIUM

G0056

Threat group.View on attack.mitre.org

About this group

PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1036.004
Masquerade Task or Service

PROMETHIUM has named services to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location

PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers.

T1078.003
Local Accounts

PROMETHIUM has created admin accounts on a compromised host.

T1189
Drive-by Compromise

PROMETHIUM has used watering hole attacks to deliver malicious versions of legitimate installers.

T1204.002
Malicious File

PROMETHIUM has attempted to get users to execute compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

T1205.001
Port Knocking

PROMETHIUM has used a script that configures the knockd service and firewall to only accept C2 connections from systems that use a specified sequence of knock ports.

T1543.003
Windows Service

PROMETHIUM has created new services and modified existing services for persistence.

T1547.001
Registry Run Keys / Startup Folder

PROMETHIUM has used Registry run keys to establish persistence.

T1553.002
Code Signing

PROMETHIUM has signed code with self-signed certificates.

T1587.002
Code Signing Certificates

PROMETHIUM has created self-signed certificates to sign malicious installers.

T1587.003
Digital Certificates

PROMETHIUM has created self-signed digital certificates for use in HTTPS C2 traffic.

Software2

Campaigns1

References3

  1. Microsoft NEODYMIUM Dec 2016 Open source
    Microsoft. (2016, December 14). Twin zero-day attacks: PROMETHIUM and NEODYMIUM target individuals in Europe. Retrieved November 27, 2017.
  2. Microsoft SIR Vol 21 Open source
    Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
  3. Talos Promethium June 2020 Open source
    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.