Strider — APT Profile
ProjectSauron (a.k.a. Strider) is a top-level modular cyber-espionage platform active since at least 2011, designed for long-term stealthy campaigns with per-victim customized implants (Remsec) and multiple exfiltration methods, including air-gap crossing via USB. It targets a small set of high-value government, defense, telecom, and research entities, with known victims in Russia, China, Sweden, Belgium, Iran, and Rwanda. Tooling and tradecraft show overlap with Equation Group, and all artifacts are customized per victim to minimize cross-victim indicators of compromise.Also tracked as
ProjectSauron, G0041
Tools & malware
- Remsec Backdoor
- win.remsec_strider Backdoor
Vendor research
- Strider: Cyberespionage group turns eye of Sauron on targets Symantec
- ProjectSauron: top level cyber-espionage platform covertly extracts encrypted government comms Kaspersky
- The ProjectSauron APT Kaspersky
Countries linked to this actor
- Rwanda targets