ProjectSauron, also known as Remsec and Strider, is a highly sophisticated modular cyber-espionage malware framework used in narrowly targeted intrusions against government, military, diplomatic, telecommunications, airline, and internet service provider entities. It is associated with long-term stealth operations and has been publicly characterized as an advanced intelligence-focused platform rather than commodity malware.
The framework is centered on the Remsec backdoor and loader architecture for Windows systems. It supports extensive host and network reconnaissance, including collection of running process information, current user information, network configuration details such as routing, ARP, and DNS cache data, and active discovery through ARP and port scanning as well as ping and traceroute functionality. It also includes security software discovery through inspection of active drivers.
ProjectSauron contains credential-access and surveillance capabilities. Documented components include a keylogger and a persistence mechanism commonly registered on domain controllers as a Windows LSA password filter, enabling harvesting of plaintext passwords during password changes. It also supports DLL injection for in-memory execution and stealth.
The malware emphasizes defense evasion and anti-forensics. Its loader and executables masquerade as legitimate Windows and third-party software components, and it can delete files and securely remove itself after collection and exfiltration. Persistence has also been achieved through scheduled tasks.
A notable feature of ProjectSauron is its ability to bridge air-gapped environments. It includes packages that collect documents from inserted USB media and has been described as capable of moving data from isolated networks to connected systems via removable drives. This places it among a small set of espionage frameworks designed for USB-mediated collection and exfiltration in disconnected environments.
ProjectSauron has also been discussed as a point of comparison for later activity clusters such as ACIDBOX, though such comparisons do not establish common authorship. Public reporting has described fewer than several dozen known victims, underscoring its selective operational use and bespoke tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In practice, Sauron operations have been largely tied to a stealthy, single variant of malware known as “Remsec,” which has been found on a small subset of victim networks.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
RedCurl mimicked legitimate file names and scheduled tasks, e.g. MicrosoftCurrentupdatesCheck and MdMMaintenenceTask to mask malicious files and scheduled tasks.
Akira has used legitimate names and locations for files to evade defenses.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
AppleSeed can find and collect data from removable media devices. APT28 backdoor may collect the entire contents of an inserted USB device. Aria-body has the ability to collect data from USB devices. BADNEWS copies files with certain extensions from USB devices to a predefined directory.
used USB drives as the physical transmission medium to transfer information across air gaps.
This “special module [was] designed to move data from air-gapped networks to Internet-connected systems,” Kaspersky researchers previously noted. “To achieve this, removable USB devices are used. Once networked systems are compromised, the attackers wait for a USB drive to be attached to the infected machine.”
55 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT malware/backdoor cited as an example of using an LSA password filter to harvest plaintext passwords on domain controllers.
... Remsec ... (v1.4→v1.5) ...
Remsec (v1.4→v1.5)
Named malware/platform referenced with aliases Strider and Sauron.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.