S0491: StrongPity
MITRE ATT&CK S0491: StrongPity Malware details for Windows, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
StrongPity is a Windows information-stealing malware family associated in ATT&CK with PROMETHIUM. Its decision value is less about a single indicator and more about the pattern: user-driven execution, persistence through Windows services or Run keys, discovery of files/processes/network/security tools, stealthy naming/encoding/deletion, and automated collection/exfiltration over web/C2 channels. For leaders, this maps directly to data-loss risk, endpoint resilience, SOC visibility, and incident response readiness.
Executive priority
Prioritize StrongPity as a validation case for whether the organization can detect and investigate Windows-based espionage-style malware before sensitive information leaves the environment. Ask whether endpoint logging, PowerShell visibility, service/registry monitoring, web egress controls, and exfiltration investigation procedures produce audit-ready evidence. Because ATT&CK provides no official detection text for this malware, coverage should be proven through control validation rather than assumed from tool deployment.
Technical view
Defenders should validate detections around the ATT&CK relationships: malicious-file execution, PowerShell use, service execution and Windows service persistence, Registry Run Keys/Startup Folder persistence, process/network/file discovery, security software discovery, ingress tool transfer, automated collection, custom archiving, automated exfiltration, exfiltration over C2, web-protocol C2, multi-hop proxy behavior, file deletion, hidden windows, masqueraded tasks/services/resources, encoded files, and code signing abuse. Treat this as a Windows endpoint plus network-egress detection problem, with investigation pivots from process lineage to persistence artifacts, collected/archive files, and outbound web communications.
Likely telemetry
- Windows endpoint process creation and parent/child process lineage
- PowerShell execution logs and command-line telemetry
- Windows service creation, modification, and service-control execution events
- Registry Run Key and Startup Folder change events
- File creation, deletion, rename, archive, and encoded/encrypted artifact telemetry
Detection direction
- Do not rely on a StrongPity-specific signature alone; ATT&CK supplies no official detection guidance for this object.
- Correlate suspicious user-opened files with follow-on PowerShell, service creation, Run key changes, file discovery, and outbound web traffic.
- Tune for service and registry persistence that uses legitimate-looking names or locations, while accounting for administrative software deployment false positives.
- Review signed binaries and trusted-looking file paths critically; code signing and masquerading relationships mean apparent legitimacy is not sufficient.
- Monitor for staged collection patterns: repeated file enumeration, custom archives or encoded files, then outbound transfer over web/C2 channels.
Mitigation priorities
- Harden initial execution paths by controlling untrusted files and reducing user execution of suspicious attachments or downloads.
- Enforce least privilege and application control where feasible to limit PowerShell misuse, service creation, and unauthorized persistence.
- Monitor and restrict high-risk persistence locations, including Windows services, Run keys, and Startup folders.
- Strengthen egress governance with proxy/DNS logging, allowlisting where appropriate, and investigation workflows for unusual web-based outbound traffic.
- Protect sensitive data with collection/exfiltration controls, including data classification, access controls, and alerting on unusual archival or transfer behavior.
Additional notes and limits
ATT&CK identifies StrongPity as information-stealing malware used by PROMETHIUM and links it to a PROMETHIUM campaign context, including a campaign description that notes Android targeting while the supplied malware platform is Windows. The most defensible defensive value comes from the listed technique relationships, not from unsupported assumptions about current activity, victimology, or indicators.
The official object has no detection text, no aliases, and no malware-specific tactics listed. External references are provided, but this take is limited to the supplied ATT&CK fields, references, and relationships. Local telemetry, asset criticality, identity context, and egress architecture are required to determine actual exposure and detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
StrongPity
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
