Project Sauron is a highly sophisticated, modular cyber-espionage malware platform focused on stealthy long-term information theft. Public reporting cited here states it operated undetected for more than five years and was discovered during an investigation into anomalous network traffic on a government network. Kaspersky reported that one component was a malicious library disguised as a Windows password filter and loaded on a domain controller; it executed during user logons and password changes and could capture plaintext passwords. The platform is described as comprising at least 50 modules that can be mixed and matched per victim, with core modules behaving as dormant "sleeper cells" until activated by commands embedded in incoming network traffic, supporting persistence and low visibility.
Reported capabilities include theft of passwords, cryptographic keys, encryption-related configuration files, IP addresses of key servers, log stores, keystroke logging, and backdoor access for remote control. Multiple sources in the content also describe an ability to collect information from air-gapped systems, including via specially prepared USB drives with hidden partitions and a virtual file system, although Kaspersky noted the exact USB-enabled exfiltration mechanism was not fully understood and any zero-day involvement remained speculative and unconfirmed. The malware reportedly varies filenames, file sizes, modules, and exfiltration methods across victims, including use of names resembling legitimate Microsoft files, making correlation and detection difficult.
Victims mentioned in the content include more than 30 organizations across government agencies, military organizations, scientific research centers, telecommunications providers, financial institutions, government embassies, and an airline. Reported victim countries include Russia, Iran, Rwanda, China, Sweden, and Belgium, with possible infections in Italian-speaking countries. The operation has been linked in reporting to an unknown threat actor referred to as Strider. Both Kaspersky and Symantec assessed the campaign as nation-state or nation-state-level in sophistication, but public attribution remained unresolved. The malware is compared in sophistication to Duqu, Flame, Equation, and Regin. The content also notes that Project Sauron embedded a Lua scripting engine.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Researchers have found advanced malware that can steal encryption keys, collect information from air-gapped computers, and record someone’s keystrokes without being detected. The researchers have no idea who designed the malware, named Project Sauron...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Designed to enable long-term campaigns through stealthy survival mechanisms coupled with multiple exfiltration methods.
Here the entry is made possible through specially prepared USB drives, which would appear to be like the usual mass storage devices, but would also contain a hidden partition with a virtual file system, which makes possible the transfer of data from air-gapped systems
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an advanced modular toolkit emblematic of the era of blockbuster malware research.
Referenced as a sophisticated malware framework that embeds Lua for modularity.
A known nation-state espionage malware/toolkit referenced for comparison with fast16.
A highly sophisticated espionage malware platform used for long-term covert intrusion and data theft. It steals passwords, encryption keys, configuration files, and log stores, logs keystrokes, opens backdoors for remote control, varies artifacts between infections to evade detection, and can exfiltrate data from air-gapped systems via specially prepared USB drives with hidden partitions and a virtual file system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.