← Back to all threat actors

PROMETHIUM

Also known as StrongPity
Tracked as G0056

PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demonstrated similarity to another activity group called NEODYMIUM due to overlapping victim and campaign characteristics.

How we source and review actor profiles
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: StrongPity

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0056

Reviewed identity mapping approved on this date.

Last observed
CampaignC0033

C0033 was a PROMETHIUM campaign during which they used StrongPity to target Android users. C0033 was the fi…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

PROMETHIUMCanonical Name
StrongPityAlias
G0056Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...