Project Sauron is a highly sophisticated modular cyber-espionage malware platform associated with the threat actor commonly tracked as Strider. It was used in long-running covert intrusions against government, military, scientific research, telecommunications, financial, diplomatic, and aviation-related organizations across multiple countries, and operated undetected for at least five years. Public reporting describes more than 30 victim organizations and emphasizes the campaign’s nation-state-level resourcing, operational security, and customization.
The platform is built from at least 50 interchangeable modules tailored per victim, with operators deliberately varying components and artifacts between infections to hinder correlation and signature-based detection. Core modules can remain dormant as sleeper cells until activated by commands embedded in incoming network traffic, supporting long-term stealth and persistence. A notable component masqueraded as a Windows password filter on a domain controller, allowing execution during logon and password-change events and enabling capture of plaintext credentials.
Project Sauron’s primary mission was intelligence collection and covert exfiltration. Reported capabilities include theft of passwords, cryptographic keys, configuration files, and log data; keylogging; remote backdoor access; and collection of information from air-gapped environments. Reporting also describes a USB-based mechanism involving hidden storage or virtualized removable-media structures to assist exfiltration from isolated systems, although the exact operation of that capability and whether it depended on an additional exploit remained unresolved publicly. The malware was also noted for using different exfiltration methods across victims and for disguising components to resemble legitimate software, further complicating detection.
The operation has not been reliably attributed to a specific state, but multiple assessments characterize it as the work of a nation-state or nation-state-level actor due to its complexity, bespoke engineering, and sustained espionage focus. Project Sauron is widely regarded as being in the same sophistication tier as major advanced espionage platforms such as Duqu, Flame, Equation, and Regin.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers have found advanced malware that can steal encryption keys, collect information from air-gapped computers, and record someone’s keystrokes without being detected. The researchers have no idea who designed the malware, named Project Sauron...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Designed to enable long-term campaigns through stealthy survival mechanisms coupled with multiple exfiltration methods.
Here the entry is made possible through specially prepared USB drives, which would appear to be like the usual mass storage devices, but would also contain a hidden partition with a virtual file system, which makes possible the transfer of data from air-gapped systems
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an advanced modular toolkit emblematic of the era of blockbuster malware research.
Referenced as a sophisticated malware framework that embeds Lua for modularity.
A known nation-state espionage malware/toolkit referenced for comparison with fast16.
This is the first time we have seen Lua used by an APT threat actor since its use by AnimalFarm and Project Sauron.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.