StrongPity

Malware family · 4 sample(s) · 4 indicator record(s) · 3 signing certificate(s) · Active 2021-05-24 → 2023-01-04 (experimental)

About StrongPity

StrongPity (aka Promethium / APT-C-41) is a long-running espionage actor known for watering-hole distribution of trojanized legitimate installers. Its Android branch, documented by ESET in 2023, ships a backdoored build of a real app (for example Shagle video-chat / Telegram-style apps) whose modular malicious component activates when a matching C2 is reachable. It harvests call logs, SMS, contacts, device and location data and files, records calls and enumerates installed apps, uploading to attacker infrastructure (internetwideband.com, networktopologymaps.com, www.upeg-system-app.com). Historically associated with Turkey/Syria-nexus targeting. APT / state-aligned.

Indicators

IndicatorTypeSampleFirst seen
internetwideband.com/user/ domain fd1aac87399a… 2021-05-24
networktopologymaps.com/user/ domain a9378a546931… 2023-01-04
networktopologymaps.com/user/ domain be9214a58046… 2021-07-22
www.upeg-system-app.com/ServiceRApp/user/ domain 596257ef017b… 2021-07-22