ProjectSauron, also known as Strider, is a highly sophisticated cyber-espionage threat actor and malware platform publicly exposed in 2016 but assessed to have operated covertly since at least 2011. The operation is widely characterized as nation-state or nation-state-level due to its technical sophistication, operational security, long dwell time, and narrowly targeted espionage mission, although reliable public attribution to a specific country remains unresolved. ProjectSauron conducted targeted intrusions against a small set of high-value organizations, including government entities, embassies, military-related targets, telecommunications providers, internet service providers, scientific research organizations, and at least one airline. Known victim geography includes Russia, Iran, Rwanda, Belgium, Sweden, and China. The campaign was notable for extensive victim-specific customization: operators varied modules, file sizes, and other implementation details across targets to reduce recognizable patterns and hinder detection and correlation. The platform associated with the actor, including the Remsec malware framework, is modular and designed for stealthy long-term post-compromise operations. Documented capabilities include keylogging, theft of encryption keys, certificates, emails, confidential files, and domain-related information, as well as collection from removable media and movement of data from air-gapped environments to connected systems. ProjectSauron used passive and active backdoors, named-pipe communications, HTTP, DNS, ICMP, raw packet transports, and internal proxy nodes on dual-homed systems to relay traffic and exfiltrate data from segmented networks without direct internet access. The framework also supported loading encrypted plugins, executing arbitrary binaries or shellcode, deep packet inspection, timestomping, firewall manipulation, and privilege escalation through abuse of vulnerable third-party drivers. A distinctive operational feature was its air-gap bridging tradecraft. Components such as MyTrampoline and BUS Manager used removable media and hidden storage structures to shuttle data between isolated and connected environments while harvesting targeted documents from USB devices. Other modules functioned as Security Provider or LSA components to maintain persistence and covertly inspect traffic or process attacker commands. Public reporting indicates fewer than 40 known victims and more than 30 affected organizations, underscoring a selective espionage campaign rather than broad opportunistic activity. After public exposure in 2016, operators reportedly began uninstalling malware from known victims, and no clearly attributable follow-on activity has been publicly confirmed. Known aliases include ProjectSauron and Strider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor associated with netsh-based proxy configuration behavior mapped to internal proxy command-and-control activity.
Referenced as a threat actor associated with the Internal Proxy command-and-control technique in this detection content.
Mentioned only as a possible (but not supported) attribution reference point due to loose technical similarities between AcidBox and Remsec; the report explicitly states attribution is not possible based on the observed overlaps.
Highly sophisticated espionage group behind ProjectSauron/Remsec, targeting a very small number of military, government, diplomatic, telecom, airline, and ISP victims worldwide with stealthy modular malware and air-gap data theft capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.