Strider
[Strider](https://attack.mitre.org/groups/G0041) is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.(Citation: Symantec Strider Blog)(Citation: Kaspersky ProjectSauron Blog)
Properties
- stix_id
- intrusion-set--277d2f87-2ae5-4730-a3aa-50c1fdff9656
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (3)
Adversaries may use a hidden file system to conceal malicious activity from users and security tools. File systems provide a structure to store and ac
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist
Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they a
Software & Tools (1)
[Remsec](https://attack.mitre.org/software/S0125) is a modular backdoor that has been used by [Strider](https://attack.mitre.org/groups/G0041) and app
Explore this actor's full graph with Ninja Signal