{"id":3424,"date":"2021-07-30T01:29:03","date_gmt":"2021-07-30T06:29:03","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3424"},"modified":"2021-08-07T12:04:49","modified_gmt":"2021-08-07T17:04:49","slug":"strongpity-an-infamous-group-of-cybercriminals","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/","title":{"rendered":"StrongPity infamous group of cybercriminals"},"content":{"rendered":"\n<p>StrongPity, an APT group active since at least 2012 and publicly reported for the first time in 2016, although they are still known as Promethium, these were the authors of the attacks on Kurdistan through watering hole attacks, these attacks consist of the infection of websites of third parties used by the end users to whom you want to compromise. It is a very common way of attacking organizations, since its success rests not so much on security flaws in the technological infrastructure itself, but on the intelligence analysis practiced on the habits of the end users.<\/p>\n\n\n\n<p>StrongPity&#8217;s APT focuses on finding and extracting data from infected machines and runs a number of bogus websites that lure users in with a variety of software tools. These tools are Trojanized versions of original applications.<\/p>\n\n\n\n<p><strong><em>\u25b8The APT selectively targets victims using a predefined IP list. If a victim&#8217;s IP address matches the one in the installer configuration file, the group delivers a Trojan version of the application, otherwise a legitimate version.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Once installed, the malware activates an exfiltration component that executes a file search mechanism with the task of looping through drives, searching for files with some specific extensions defined by the attackers.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8If found, the files are stored in a temporary file (.ZIP). Then divide them into hidden encrypted files (.SFT) and send them to the C2 server. Finally, these files are removed from the disk to hide any evidence of exfiltration.<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8The APT uses two types of servers: download servers that propagate the malicious installer used in the initial compromise of victims, and C2 servers.<\/em><\/strong><\/p>\n\n\n\n<p>For now, it seems that StrongPity It wants to expand territory as recently, an investigation was conducted on a malicious Android malware sample, believed to be attributable to this group, which was posted on the Syrian e-Gov website. As far as we know, this is the first time that the group has been publicly observed using malicious Android applications as part of their attacks, but we will know that when they publish more about this threat.<\/p>\n\n\n\n<p>Also see:<br><a href=\"https:\/\/truxgoservers.com\/blog\/prometheus-and-grief-2-new-ransomware-groups\/\">Prometheus and Grief, 2 New Ransomware Groups<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/\">FIN7, a dangerous group of hackers<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>StrongPity, an APT group active since at least 2012 and publicly reported for the first time in 2016, although they are still known as Promethium, these were the authors of the attacks on Kurdistan through watering hole attacks, these attacks consist of the infection of websites of third parties used by the end users to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3425,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3424","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>StrongPity infamous group of cybercriminals - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Today we have to see StrongPity, an APT group active since at least 2012 which has already had a leading role many times due to its threats..\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"StrongPity infamous group of cybercriminals - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Today we have to see StrongPity, an APT group active since at least 2012 which has already had a leading role many times due to its threats..\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-30T06:29:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-07T17:04:49+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/new-4.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1120\" \/>\n\t<meta property=\"og:image:height\" content=\"633\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"StrongPity infamous group of cybercriminals\",\"datePublished\":\"2021-07-30T06:29:03+00:00\",\"dateModified\":\"2021-08-07T17:04:49+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/\"},\"wordCount\":360,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/new-4.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/\",\"name\":\"StrongPity infamous group of cybercriminals - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/new-4.jpg\",\"datePublished\":\"2021-07-30T06:29:03+00:00\",\"dateModified\":\"2021-08-07T17:04:49+00:00\",\"description\":\"Today we have to see StrongPity, an APT group active since at least 2012 which has already had a leading role many times due to its threats..\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/new-4.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/new-4.jpg\",\"width\":1120,\"height\":633},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/strongpity-an-infamous-group-of-cybercriminals\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"StrongPity infamous group of cybercriminals\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"StrongPity infamous group of cybercriminals - Truxgo Server Blog","description":"Today we have to see StrongPity, an APT group active since at least 2012 which has already had a leading role many times due to its threats..","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/","og_locale":"es_MX","og_type":"article","og_title":"StrongPity infamous group of cybercriminals - Truxgo Server Blog","og_description":"Today we have to see StrongPity, an APT group active since at least 2012 which has already had a leading role many times due to its threats..","og_url":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-07-30T06:29:03+00:00","article_modified_time":"2021-08-07T17:04:49+00:00","og_image":[{"width":1120,"height":633,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/new-4.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"StrongPity infamous group of cybercriminals","datePublished":"2021-07-30T06:29:03+00:00","dateModified":"2021-08-07T17:04:49+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/"},"wordCount":360,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/new-4.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/","url":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/","name":"StrongPity infamous group of cybercriminals - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/new-4.jpg","datePublished":"2021-07-30T06:29:03+00:00","dateModified":"2021-08-07T17:04:49+00:00","description":"Today we have to see StrongPity, an APT group active since at least 2012 which has already had a leading role many times due to its threats..","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/new-4.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/07\/new-4.jpg","width":1120,"height":633},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"StrongPity infamous group of cybercriminals"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3424"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3424\/revisions"}],"predecessor-version":[{"id":3497,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3424\/revisions\/3497"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3425"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}