StrongPity, an APT group active since at least 2012 and publicly reported for the first time in 2016, although they are still known as Promethium, these were the authors of the attacks on Kurdistan through watering hole attacks, these attacks consist of the infection of websites of third parties used by the end users to whom you want to compromise. It is a very common way of attacking organizations, since its success rests not so much on security flaws in the technological infrastructure itself, but on the intelligence analysis practiced on the habits of the end users.

StrongPity’s APT focuses on finding and extracting data from infected machines and runs a number of bogus websites that lure users in with a variety of software tools. These tools are Trojanized versions of original applications.

▸The APT selectively targets victims using a predefined IP list. If a victim’s IP address matches the one in the installer configuration file, the group delivers a Trojan version of the application, otherwise a legitimate version.

▸Once installed, the malware activates an exfiltration component that executes a file search mechanism with the task of looping through drives, searching for files with some specific extensions defined by the attackers.

▸If found, the files are stored in a temporary file (.ZIP). Then divide them into hidden encrypted files (.SFT) and send them to the C2 server. Finally, these files are removed from the disk to hide any evidence of exfiltration.

▸The APT uses two types of servers: download servers that propagate the malicious installer used in the initial compromise of victims, and C2 servers.

For now, it seems that StrongPity It wants to expand territory as recently, an investigation was conducted on a malicious Android malware sample, believed to be attributable to this group, which was posted on the Syrian e-Gov website. As far as we know, this is the first time that the group has been publicly observed using malicious Android applications as part of their attacks, but we will know that when they publish more about this threat.

Also see:
Prometheus and Grief, 2 New Ransomware Groups
FIN7, a dangerous group of hackers


Un comentario en «StrongPity infamous group of cybercriminals»

Deja un comentario

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *