Threat actor · all actors
PROMETHIUMG0056 state
🇹🇷 TR
aka PROMETHIUM, StrongPity, G0056, APT-C-41
Last updated: 2026-08-20
About this actor
[PROMETHIUM](https://attack.mitre.org/groups/G0056) is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. [PROMETHIUM](https://attack.mitre.org/groups/G0056) has demonstrated similarity to another activity group called [NEODYMIUM](https://attack.mitre.org/groups/G0055) due to overlapping victim and campaign characteristics.(Citation: Microsoft NEODYMIUM Dec 2016)(Citation: Microsoft SIR Vol 21)(Citation: Talos Promethium June 2020)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 19 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2022 — 4 KEV added
- 2015 — 1 CVE published
- 2013 — 2 CVE published
- 2012 — 1 CVE published
- 2011 — 1 CVE published
- 2010 — 6 CVE published
- 2008 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2010-0840 KEV | 9.9 | 9.8 | 0.9632 | 2010-04-01 | see CVE |
CVE-2010-0188 KEV | 8.5 | 7.8 | 0.9751 | 2010-02-22 | see CVE |
CVE-2010-1297 KEV | 8.5 | 7.8 | 0.9339 | 2010-06-08 | see CVE |
CVE-2010-2568 KEV | 8.5 | 7.8 | 0.9734 | 2010-07-22 | see CVE |
CVE-2008-2551 | 8.0 | 0.0 | 0.9528 | 2008-06-04 | see CVE |
CVE-2010-3336 | 8.0 | 0.0 | 0.8625 | 2010-11-10 | see CVE |
CVE-2010-3653 | 8.0 | 0.0 | 0.9277 | 2010-10-26 | see CVE |
CVE-2011-0097 | 8.0 | 0.0 | 0.9467 | 2011-04-13 | see CVE |
CVE-2012-0056 | 8.0 | 0.0 | 0.7871 | 2012-01-27 | see CVE |
CVE-2013-1493 | 8.0 | 0.0 | 0.9645 | 2013-03-05 | see CVE |
CVE-2013-2460 | 8.0 | 0.0 | 0.9710 | 2013-06-18 | see CVE |
CVE-2015-0072 | 8.0 | 0.0 | 0.9689 | 2015-02-07 | see CVE |
T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1036.005Match Legitimate Resource Name or Location ↗T1078Valid Accounts ↗T1078.003Local Accounts ↗T1189Drive-by Compromise ↗T1204User Execution ↗T1204.002Malicious File ↗T1205Traffic Signaling ↗T1205.001Port Knocking ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1587Develop Capabilities ↗T1587.002Code Signing Certificates ↗T1587.003Digital Certificates ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 11 / 19 | 58% |
SI-4 | 11 / 19 | 58% |
CA-7 | 10 / 19 | 53% |
AC-3 | 9 / 19 | 47% |
CM-2 | 9 / 19 | 47% |
CM-7 | 9 / 19 | 47% |
AC-6 | 8 / 19 | 42% |
AC-2 | 7 / 19 | 37% |
SI-7 | 7 / 19 | 37% |
SC-7 | 6 / 19 | 32% |
SI-3 | 6 / 19 | 32% |
AC-4 | 5 / 19 | 26% |
CM-5 | 5 / 19 | 26% |
SI-10 | 5 / 19 | 26% |
AC-5 | 4 / 19 | 21% |
Co-occurring actors
Similar actors
Similar TTPs
- Naikon 0.24
- Carbanak 0.22
- Operation Sharpshooter 0.21
- Darkhotel 0.20
- RTM 0.19
Active in same years
- NEODYMIUM 7.00
- Equation 4.00
- APT29 2.00
- Naikon 2.00
- Threat Group-3390 2.00
Same nation-state
- C0033 1.00
- Sea Turtle 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00