Strider

G0041

Threat group.View on attack.mitre.org

About this group

Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1090.001
Internal Proxy

Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access.

T1556.002
Password Filter DLL

Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password.

T1564.005
Hidden File System

Strider has used a hidden file system that is stored as a file on disk.

Software1

Campaigns0

None recorded.

References2

  1. Kaspersky ProjectSauron Blog Open source
    Kaspersky Lab's Global Research & Analysis Team. (2016, August 8). ProjectSauron: top level cyber-espionage platform covertly extracts encrypted government comms. Retrieved August 17, 2016.
  2. Symantec Strider Blog Open source
    Symantec Security Response. (2016, August 7). Strider: Cyberespionage group turns eye of Sauron on targets. Retrieved August 17, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.