Threat group.View on attack.mitre.org
Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.
| Technique | Procedure example |
|---|---|
| T1090.001 Internal Proxy |
Strider has used local servers with both local network and Internet access to act as internal proxy nodes to exfiltrate data from other parts of the network without direct Internet access. |
| T1556.002 Password Filter DLL |
Strider has registered its persistence module on domain controllers as a Windows LSA (Local System Authority) password filter to acquire credentials any time a domain, local user, or administrator logs in or changes a password. |
| T1564.005 Hidden File System |
Strider has used a hidden file system that is stored as a file on disk. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.