Strider
Also known as: ProjectSauron
Overview
Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.
Naming & attribution
Strider is tracked under 2 names across the industry. It uses 3 documented ATT&CK techniques — more than 8% of the 174 groups tracked here. Activity attributed since at least 2011.
| Name | First reported by |
|---|---|
| ProjectSauron | Kaspersky Lab's Global Research & Analysis Team |
| Strider | Symantec Security Response |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1564.005Hidden File System — used by 2 of 174 groups -
T1556.002Password Filter DLL — used by 3 of 174 groups
Targets
Government · Intelligence · Military
Regions
Belgium · China · Iran · Russia · Rwanda · Sweden
TTPs — 3 techniques across 3 tactics
Stealth
-
T1564.005Hidden File System
Defense Impairment
-
T1556.002Password Filter DLL
Command and Control
-
T1090.001Internal Proxy
Tools & malware (1)
Remsec
Reporting (3)
- The ProjectSauron APT — Kaspersky Lab's Global Research & Analysis Team
- ProjectSauron: top level cyber-espionage platform covertly extracts encrypted government comms — Kaspersky Lab's Global Research & Analysis Team
- Strider: Cyberespionage group turns eye of Sauron on targets — Symantec Security Response