Meta tags:
Headings (most frequently used words):
strongpity, techniques, used, groups, that, use, this, software, campaigns, references, enterprise, layer,
Text of the page (most frequently used words):
#enterprise (31), strongpity (31), can (18), the (15), att (11), and (11), software (11), all (10), has (10), files (9), file (8), use (7), for (6), discovery (6), ics (5), mobile (5), none (5), 2020 (5), with (5), compromised (5), service (5), used (5), windows (5), mitre (4), data (4), techniques (4), tools (4), name (4), legitimate (4), 002 (4), services (4), identify (4), host (4), its (4), 001 (4), 003 (4), encrypted (4), version (4), are (3), campaigns (3), groups (3), cti (3), detection (3), defenses (3), promethium (3), july (3), been (3), user (3), execution (3), system (3), proxy (3), hide (3), collected (3), malware (3), list (3), archive (3), 2026 (2), corporation (2), domains (2), resources (2), reference (2), components (2), analytics (2), strategies (2), assets (2), mitigations (2), tactics (2), matrices (2), core (2), objects (2), june (2), apt (2), retrieved (2), infrastructure (2), references (2), c0033 (2), that (2), via (2), installation (2), applications (2), security (2), signed (2), multiple (2), layers (2), process (2), component (2), information (2), https (2), over (2), port (2), location (2), masquerading (2), 004 (2), hard (2), download (2), from (2), window (2), search (2), extensions (2), exfiltrate (2), documents (2), exfiltration (2), channel (2), add (2), defender (2), exclusions (2), modify (2), created (2), modified (2), persistence (2), powershell (2), registry (2), run (2), automatically (2), automated (2), layer (2), s0491 (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, sub, mercer, extends, global, reach, strongpity3, tudorica, revealing, trojanized, working, hours, description, g0056, this, executed, including, compression, browsers, recovery, other, utilities, malicious, t1204, install, execute, itself, t1569, address, network, configuration, t1016, self, certificates, code, signing, subvert, trust, controls, t1553, eset, bitdefender, antivirus, installed, before, dropping, payload, t1518, servers, terminal, nodes, multi, hop, t1090, determine, logged, checking, see, explorer, exe, running, t1057, strings, dropper, encoded, obfuscated, 013, t1027, 1402, communication, non, standard, t1571, bundled, disguise, match, resource, 005, named, appear, masquerade, task, t1036, disk, volume, serial, number, local, storage, t1680, specified, targets, ingress, tool, transfer, t1105, delete, previously, exfiltrated, deletion, indicator, removal, t1070, ability, console, document, module, hidden, artifacts, t1564, parse, drive, specific, directory, t1083, through, channels, t1041, traffic, using, ssl, tls, asymmetric, cryptography, t1573, directories, prevent, disable, t1685, new, existing, create, t1543, command, scripting, interpreter, t1059, key, hkcu, microsoft, currentversion, keys, startup, folder, boot, logon, autostart, t1547, server, t1020, searcher, collect, based, predefined, collection, t1119, compress, encrypt, archived, into, sft, repeated, xor, encryption, scheme, custom, method, t1560, http, communications, web, protocols, application, protocol, t1071, domain, view, navigator, live, permalink, april, 2024, last, platforms, type, stealing, home, open, join, october, mclean, hotel, details, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, more, about, get, started, detections,
Text of the page (random words):
strongpity software s0491 mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home software strongpity strongpity strongpity is an information stealing malware used by promethium 1 2 id s0491 ⓘ type malware ⓘ platforms windows version 1 1 created 20 july 2020 last modified 10 april 2024 version permalink live version att ck navigator layers enterprise layer download view techniques used domain id name use enterprise t1071 001 application layer protocol web protocols strongpity can use http and https in c2 communications 2 1 enterprise t1560 003 archive collected data archive via custom method strongpity can compress and encrypt archived files into multiple sft files with a repeated xor encryption scheme 2 1 enterprise t1119 automated collection strongpity has a file searcher component that can automatically collect and archive files based on a predefined list of file extensions 1 enterprise t1020 automated exfiltration strongpity can automatically exfiltrate collected documents to the c2 server 2 1 enterprise t1547 001 boot or logon autostart execution registry run keys startup folder strongpity can use the hkcu software microsoft windows currentversion run registry key for persistence 2 enterprise t1059 001 command and scripting interpreter powershell strongpity can use powershell to add files to the windows defender exclusions list 2 enterprise t1543 003 create or modify system process windows service strongpity has created new services and modified existing services for persistence 2 enterprise t1685 disable or modify tools strongpity can add directories used by the malware to the windows defender exclusions list to prevent detection 2 enterprise t1573 002 encrypted channel asymmetric cryptography strongpity has encrypted c2 traffic using ssl tls 2 enterprise t1041 exfiltration over c2 channel strongpity can exfiltrate collected documents through c2 channels 2 1 enterprise t1083 file and directory discovery strongpity can parse the hard drive on a compromised host to identify specific file extensions 2 enterprise t1564 003 hide artifacts hidden window strongpity has the ability to hide the console window for its document search module from the user 2 enterprise t1070 004 indicator removal file deletion strongpity can delete previously exfiltrated files from the compromised host 2 1 enterprise t1105 ingress tool transfer strongpity can download files to specified targets 1 enterprise t1680 local storage discovery strongpity can identify the hard disk volume serial number on a compromised host 2 enterprise t1036 004 masquerading masquerade task or service strongpity has named services to appear legitimate 2 1 005 masquerading match legitimate resource name or location strongpity has been bundled with legitimate software installation files for disguise 2 enterprise t1571 non standard port strongpity has used https over port 1402 in c2 communication 1 enterprise t1027 013 obfuscated files or information encrypted encoded file strongpity has used encrypted strings in its dropper component 2 1 enterprise t1057 process discovery strongpity can determine if a user is logged in by checking to see if explorer exe is running 2 enterprise t1090 003 proxy multi hop proxy strongpity can use multiple layers of proxy servers to hide terminal nodes in its infrastructure 1 enterprise t1518 001 software discovery security software discovery strongpity can identify if eset or bitdefender antivirus are installed before dropping its payload 2 enterprise t1553 002 subvert trust controls code signing strongpity has been signed with self signed certificates 1 enterprise t1016 system network configuration discovery strongpity can identify the ip address of a compromised host 2 enterprise t1569 002 system services service execution strongpity can install a service to execute itself as a service 2 1 enterprise t1204 002 user execution malicious file strongpity has been executed via compromised installation files for legitimate software including compression applications security software browsers file recovery applications and other tools and utilities 2 1 groups that use this software id name references g0056 promethium 1 2 campaigns id name description c0033 c0033 2 1 references tudorica r et al 2020 june 30 strongpity apt revealing trojanized tools working hours and infrastructure retrieved july 20 2020 mercer w et al 2020 june 29 promethium extends global reach with strongpity3 apt retrieved july 20 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|