STRIDER
G0041
UNKNOWN (STATE-SPONSORED)
PROJECTSAURON
Threat IntelligenceAPTApril 10, 2025

Strider Threat Profile

Highly sophisticated group using air-gap-defeating modular malware platform active since 2011, discovered by Kaspersky in 2016.

Highly sophisticated group using air-gap-defeating modular malware platform active since 2011, discovered by Kaspersky in 2016. This profile is mapped to MITRE ATT&CK G0041 and covers attribution, tooling, targeting, and defensive recommendations based on observed campaigns.

Overview & Attribution

Strider (also tracked as ProjectSauron) is a threat group attributed to Unknown (state-sponsored). The group primarily targets Government, military, telecoms, scientific for intelligence collection and operational objectives aligned with state interests.

MITRE ATT&CK Reference

This group is tracked as G0041 in the MITRE ATT&CK framework. All techniques referenced in this report are mapped to ATT&CK for consistent threat modeling and detection engineering.

Arsenal & Tools

Known tools and malware associated with Strider include:

Targeting & Operations

Strider operations focus on Government, military, telecoms, scientific. The group typically gains initial access through spear-phishing, exploitation of public-facing applications, or strategic web compromises before deploying custom implants for persistent access and data exfiltration.

Targeting Advisory

Organizations in the Government sector should treat Strider as a relevant threat and validate their detection coverage against the MITRE ATT&CK techniques listed below.

MITRE ATT&CK Mapping

Key techniques observed in Strider operations:

Technique IDTechnique NameTactical Context
T1091T1091Observed in Strider campaigns
T1059.001T1059.001Observed in Strider campaigns
T1027T1027Observed in Strider campaigns
T1056.001T1056.001Observed in Strider campaigns

Full ATT&CK mapping: https://attack.mitre.org/groups/G0041/

Notable Campaigns

This threat group has been active in operations targeting Government, military, telecoms, scientific. Security researchers have documented campaigns involving Remsec/ProjectSauron platform and other tools deployed against organizations in multiple countries. Attribution confidence varies by campaign, but consistent infrastructure and TTP overlap links activity to Unknown (state-sponsored)-nexus operations.

Detection & Defense

Recommended defensive measures against Strider:

How Mjolnir Security Can Help

Defend Against Strider

Mjolnir Security provides tailored threat intelligence, detection engineering, and incident response services to help organizations defend against Unknown (state-sponsored)-nexus threat actors.

Threat Intelligence Detection Engineering Incident Response Red Team Assessment Threat Hunting

Contact us: mjolnirsecurity.com

Written by: Mjolnir Security  |  Published: April 10, 2025