Strider is the name used by researchers for the unknown threat actor behind the ProjectSauron cyber-espionage platform. ProjectSauron is the more widely recognized campaign/malware name in public reporting. Kaspersky Lab and Symantec described the actor as a highly sophisticated, likely nation-state or nation-state-level espionage group, but public attribution to a specific country or service remains unresolved. Public reporting states the operation ran undetected from at least June 2011 until its exposure in 2016. Known victims included fewer than 40 organizations, with Kaspersky aware of more than 30 attacked organizations. Reported targets included government and military organizations, embassies, telecom companies, scientific research centers, an airline, and foreign internet service providers. Infections were reported in Russia, Iran, Rwanda, Belgium, Sweden, China, and likely other countries. The actor used a highly modular and customized malware platform designed for long-term stealth. Reported capabilities included theft of confidential files, emails, software certificates, encryption keys, and domain-related information; keystroke logging; credential and key material collection; deep packet inspection/network sniffing; execution of arbitrary binaries and shellcode; and covert command-and-control over multiple transports including named pipes, HTTP, DNS, ICMP, raw packets, and local proxying. Kaspersky’s technical analysis also described Lua-based orchestration, encrypted/compressed plugin loading, timestomping, use of vulnerable third-party drivers for privilege escalation/kernel execution, and specialized modules for removable-media operations. A notable capability was collection from air-gapped environments. Reporting states ProjectSauron could collect information from air-gapped computers and move data via removable USB devices. Kaspersky documented the MyTrampoline module, which used a hidden shadow filesystem on removable media to transfer data between air-gapped and internet-connected networks, and a BUS Manager package that collected targeted documents from inserted USB drives. Operational security was a defining characteristic. Researchers reported that Strider used different file sizes, names, and modules for each target, removing recognizable patterns and making discovery difficult. Symantec stated the group was capable of creating custom malware tools. The actor also used internal proxying: Strider used local servers with both local network and internet access as internal proxy nodes to exfiltrate data from network segments without direct internet access. The malware associated with the campaign is also referred to as Remsec in some reporting. One article noted loose similarities between other malware and Remsec/ProjectSauron tradecraft, but stated attribution to the ProjectSauron threat actor was not possible on that basis. Aliases directly reflected in the content are Strider and ProjectSauron.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor associated with netsh-based proxy configuration behavior mapped to internal proxy command-and-control activity.
Referenced as a threat actor associated with the Internal Proxy command-and-control technique in this detection content.
Mentioned only as a possible (but not supported) attribution reference point due to loose technical similarities between AcidBox and Remsec; the report explicitly states attribution is not possible based on the observed overlaps.
Highly sophisticated espionage group behind ProjectSauron/Remsec, targeting a very small number of military, government, diplomatic, telecom, airline, and ISP victims worldwide with stealthy modular malware and air-gap data theft capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.