NEW: Group Profiler — instant APT intel lookup. Try it →

Strider

G0041 China Espionage MITRE ATT&CK →

Also known as: ProjectSauron

Overview

Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.

Naming & attribution

Strider is tracked under 2 names across the industry. It uses 3 documented ATT&CK techniques — more than 8% of the 174 groups tracked here. Activity attributed since at least 2011.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
ProjectSauronKaspersky Lab's Global Research & Analysis Team
StriderSymantec Security Response

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1564.005 Hidden File System — used by 2 of 174 groups
  • T1556.002 Password Filter DLL — used by 3 of 174 groups

Targets

Government · Intelligence · Military

Regions

Belgium · China · Iran · Russia · Rwanda · Sweden

TTPs — 3 techniques across 3 tactics

Stealth

Defense Impairment

Command and Control

Tools & malware (1)

Remsec

Reporting (3)