Intelligence View
Strider Cyberespionage Group Hit Seven Targets in China, Russia, Belgium, Sweden
A cyber-espionage group has hit at least seven companies across four countries since October 2011, utilizing its homegrown malware, called Remsec, a backdoor trojan. According to Symantec, the group, nicknamed Strider, has hit four…
According to Symantec, the group, nicknamed Strider, has hit four companies in Russia, and one in Belgium (embassy), Sweden, and China (airline). At the operation level, Symantec had noted some vague similarities with the Flamer group because they both utilized malware based on Lua modules.
Additionally, one of Strider's targets was also infected with the Regin backdoor malware in the past. Other than these two details, there are no other links to other cyber-espionage campaigns, and Symantec has not ventured into giving any attribution to the attacks to any specific country or industrial espionage criminal group.
Strider uses Remcos malware to compromise targets
All Strider attacks have been carried out with the Remcos backdoor trojan. This malware ...
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - Strider Cyberespionage Group Hit Seven Targets in China, Russia, Belgium, Sweden
id: c8542448-f527-4337-beae-bff61b6f6315
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "Strider Cyberespionage Group H" ascii wide
condition:
any of them
}tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Strider Cyberespionage Group Hit Seven T.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
SOCIAL SHARE CARD GENERATOR