Strider

MITRE ATT&CK: G0041 View on attack.mitre.org

Aliases: ProjectSauron, Strider, Sauron, Project Sauron

First seen
2011-01-01 00:00:00
Origin
US
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
103 (101 malicious)
Last IoC activity
2026-09-02 00:38:30
Profile updated
2026-07-07 12:31:51

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ru country_code:cn country_code:se country_code:be country_code:ir country_code:rw

Context

Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.

Recent IoC activity

101 malicious indicators in Maltiverse are attributed to Strider (G0041). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname www.nullsecurity.net 2026-09-03 1
hostname ns-3.open.ro 2026-09-03 1
hostname autodiscover.email 2026-09-03 1
hostname autodiscover.exchange 2026-09-03 1
hostname autoconfig.email 2026-09-03 1
hostname mail.pics 2026-09-03 1
hostname prod.tools 2026-09-02 1
hostname webdisk.us 2026-09-02 1
hostname autodiscover.host 2026-09-02 1
hostname admin.dev 2026-09-02 1
hostname autodiscover.it 2026-09-02 1
hostname made.by 2026-09-02 1
hostname www.cantrip.org 2026-09-02 1
hostname test.support 2026-09-02 1
hostname mail.news 2026-09-02 1
hostname webdisk.it 2026-09-02 1
hostname webdisk.de 2026-09-02 1
hostname autodiscover.online 2026-09-02 1
hostname secure.dev 2026-09-02 1
hostname autodiscover.de 2026-09-02 1

Detection coverage

  • 1 YARA rules
  • 9 Sigma rules

Malware & tools used

  • Internal Proxy (attack-pattern)
  • Password Filter DLL (attack-pattern)
  • Hidden File System (attack-pattern)
  • Remsec (malware)

Reports & references

  • Kaspersky — Faq The Projectsauron Apt (report)
  • cfr.org — Project Sauron (report)
  • Broadcom/Symantec — Viewdocument (report)
  • media.kasperskycontenthub.com — The Projectsauron Apt Research Kl (report)
  • MITRE ATT&CK — G0041 (report)
  • Broadcom/Symantec — Strider Cyberespionage Group Turns Eye Sauron Targets (report)
  • Kaspersky — 75533 (report)
  • Kaspersky — The Projectsauron Apt Research Kl (report)

External references