Open Threat Intel Archive
OTIA
Indicators
ATT&CK
Threat actors
MITRE ATT&CK intrusion sets
Malware & tools
Software families & tooling
Techniques
Tactics & techniques
Reports
Sources
Developers
JSON API
Free CORS-enabled endpoints
MCP server
Model Context Protocol access
Source code
This project on GitHub
Loading the archive…
Open Threat Intel Archive
← Malware & tools
S0491
malware
StrongPity
StrongPity is an information stealing malware used by PROMETHIUM.
Platforms
Windows
MITRE ATT&CK ↗
Linked entities · 24
uses
T1020
Automated Exfiltration
uses
T1564.003
Hidden Window
uses
T1571
Non-Standard Port
uses
T1016
System Network Configuration Disc…
uses
T1041
Exfiltration Over C2 Channel
uses
T1560.003
Archive via Custom Method
uses
T1036.004
Masquerade Task or Service
uses
T1027.013
Encrypted/Encoded File
uses
T1204.002
Malicious File
uses
T1071.001
Web Protocols
uses
T1070.004
File Deletion
uses
T1518.001
Security Software Discovery
uses
T1083
File and Directory Discovery
uses
T1119
Automated Collection
uses
T1059.001
PowerShell
uses
T1543.003
Windows Service
uses
T1573.002
Asymmetric Cryptography
uses
T1680
Local Storage Discovery
uses
T1685
Disable or Modify Tools
uses
T1090.003
Multi-hop Proxy
uses
T1105
Ingress Tool Transfer
uses
T1547.001
Registry Run Keys / Startup Folder
uses
T1057
Process Discovery
uses
T1569.002
Service Execution