Strider: Cyberespionage group turns eye of Sauron on targets
ID: 3e34dcef-4b6d-4d21-bdfd-5d161b8b5b65
STIX ID: report--3e34dcef-4b6d-4d21-bdfd-5d161b8b5b65
Threat Score
80/100
Uploaded: 2026-08-19
Published Date: 2018-08-10
Last Modified Date: 2018-08-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec describes 'Strider', a low-profile cyberespionage group active since at least 2011 that uses a sophisticated modular backdoor called Remsec to conduct targeted spying (36 infections across 7 organizations in four countries). Remsec components include memory-resident executable blobs, Lua-based modules (network/host loaders and a keylogger referencing “Sauron”), multiple backdoor channels (ICMP/RAW/HTTP/pipes), and capabilities for lateral movement and data exfiltration; Symantec provides detection as Backdoor.Remsec and published IOCs to help defenders.
