not MITRE’s ATT&CK Group
NEODYMIUM
How MITRE ATT&CK characterizes this group1: NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to overlapping victim and campaign characteristics. NEODYMIUM is reportedly associated closely with BlackOasis operations, but evidence that the group names are aliases has not been identified.
Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.
Motivation not classified from the public record.
We could not place this actor into a coarse motivation tier from ATT&CK’s intrusion-set type and description prose. That uncertainty is itself a finding — the tradecraft below is still cited; the “why” is a coverage gap. All tradecraft below is sourced to MITRE ATT&CK.
Known for
— signature moves, each sourced to ATT&CKTradecraft heatmap
— ATT&CK techniques mapped onto the five attacker-outcome narrativesNo techniques are recorded for this group in the ATT&CK snapshot below — the tradecraft heatmap is empty. That is an honest coverage gap (sparse / legacy / revoked group), never a claim that the actor does nothing.1
Arsenal
— named tools & malware ATT&CK attributes to this groupCampaign highlights
— attributed operations in the ATT&CK recordNo attributed campaigns — coverage gap
Latest activity
— with explicit confidence, and what we cannot yet claimsnapshot
The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.