Netskope Threat Labs

StrongPity

ATP Sandbox Adv. Heuristics

StrongPity is an information stealing malware used by the PROMETHIUM threat actor in its intrusion campaigns.

First seen
March 2022
Last seen
October 2026

26 techniques across 8 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1057Process Discovery
  • T1083File and Directory Discovery
  • T1518Software Discovery
  • T1680Local Storage Discovery

TA0009 Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1020Automated Exfiltration
  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
Win32.Backdoor.StrongPity
Win32.Spyware.StrongPity
Win32.Trojan.StrongPity