ATT&CKSoftwareStrongPity

StrongPity

S0491

Malware.View on attack.mitre.org

About this malware

StrongPity is an information stealing malware used by PROMETHIUM.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1016
System Network Configuration Discovery

StrongPity can identify the IP address of a compromised host.

T1020
Automated Exfiltration

StrongPity can automatically exfiltrate collected documents to the C2 server.

T1027.013
Encrypted/Encoded File

StrongPity has used encrypted strings in its dropper component.

T1036.004
Masquerade Task or Service

StrongPity has named services to appear legitimate.

T1036.005
Match Legitimate Resource Name or Location

StrongPity has been bundled with legitimate software installation files for disguise.

T1041
Exfiltration Over C2 Channel

StrongPity can exfiltrate collected documents through C2 channels.

T1057
Process Discovery

StrongPity can determine if a user is logged in by checking to see if explorer.exe is running.

T1059.001
PowerShell

StrongPity can use PowerShell to add files to the Windows Defender exclusions list.

T1070.004
File Deletion

StrongPity can delete previously exfiltrated files from the compromised host.

T1071.001
Web Protocols

StrongPity can use HTTP and HTTPS in C2 communications.

T1083
File and Directory Discovery

StrongPity can parse the hard drive on a compromised host to identify specific file extensions.

T1090.003
Multi-hop Proxy

StrongPity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure.

T1105
Ingress Tool Transfer

StrongPity can download files to specified targets.

T1119
Automated Collection

StrongPity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions.

T1204.002
Malicious File

StrongPity has been executed via compromised installation files for legitimate software including compression applications, security software, browsers, file recovery applications, and other tools and utilities.

View all 26 procedure examples

Groups that use it1

Campaigns1

References2

  1. Bitdefender StrongPity June 2020 Open source
    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.
  2. Talos Promethium June 2020 Open source
    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.