LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0125: Remsec

Remsec is a modular backdoor that has been used by Strider and appears to have been designed primarily for espionage purposes. Many of its modules are written in Lua. [1]

EnterpriseS0125MalwareObject v1.5Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0125: Remsec describes [Remsec](https://attack.mitre.org/software/S0125) is a modular backdoor that has been used by [Strider](https://attack.mitre.org/groups/G0041) and appears to have been designed primarily for espionage purposes. Many of its modules are written in Lua. (Citation: Symantec Strider Blog)

Executive priority

S0125: Remsec is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0125: Remsec by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0125: Remsec appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Remsec

Remsec is a modular backdoor that has been used by Strider and appears to have been designed primarily for espionage purposes. Many of its modules are written in Lua. [1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

30 rows
DomainIDNameRelationship / procedure
EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Remsec can perform DLL injection.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1068Exploitation for Privilege Escalation

Remsec has a plugin to drop and execute vulnerable Outpost Sandbox or avast! Virtualization drivers in order to gain kernel mode privileges.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1052.001Exfiltration over USBSub-technique

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.CitationKaspersky ProjectSauron Full Report

EnterpriseT1083File and Directory Discovery

Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Full ReportCitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1686.003Windows Host FirewallSub-technique

Remsec can add or remove applications or ports on the Windows firewall or disable it entirely.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolSub-technique

Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel.CitationKaspersky ProjectSauron Full Report

EnterpriseT1049System Network Connections Discovery

Remsec can obtain a list of active connections and open ports.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1070.004File DeletionSub-technique

Remsec is capable of deleting files on the victim. It also securely removes itself after collecting and exfiltrating data.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Full ReportCitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1056.001KeyloggingSub-technique

Remsec contains a keylogger component.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1057Process Discovery

Remsec can obtain a process list from the victim.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1556.002Password Filter DLLSub-technique

Remsec harvests plain-text credentials as a password filter registered on domain controllers.CitationKaspersky ProjectSauron Full Report

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.CitationComputerWeekly StriderCitationKaspersky ProjectSauron Full Report

EnterpriseT1095Non-Application Layer Protocol

Remsec is capable of using ICMP, TCP, and UDP for C2.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Full Report

EnterpriseT1018Remote System Discovery

Remsec can ping or traceroute a remote host.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1071.003Mail ProtocolsSub-technique

Remsec is capable of using SMTP for C2.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Full ReportCitationKaspersky ProjectSauron Technical AnalysisCitationThreatpost Sauron

EnterpriseT1059.011LuaSub-technique

Remsec can use modules written in Lua for execution.CitationKaspersky Lua

EnterpriseT1105Ingress Tool Transfer

Remsec contains a network loader to receive executable modules from remote attackers and run them on the local victim. It can also upload and download files over HTTP and HTTPS.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1003.002Security Account ManagerSub-technique

Remsec can dump the SAM database.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1025Data from Removable Media

Remsec has a package that collects documents from any inserted USB sticks.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1053.005Scheduled TaskSub-technique

Remsec schedules the execution one of its modules by creating a new scheduler task.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1082System Information Discovery

Remsec can obtain the OS version information, computer name, processor architecture, machine role, and OS edition.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1087.001Local AccountSub-technique

Remsec can obtain a list of users.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1016System Network Configuration Discovery

Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1033System Owner/User Discovery

Remsec can obtain information about the current user.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1652Device Driver Discovery

Remsec has a plugin to detect active drivers of some security products.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1071.001Web ProtocolsSub-technique

Remsec is capable of using HTTP and HTTPS for C2.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Full ReportCitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1046Network Service Discovery

Remsec has a plugin that can perform ARP scanning as well as port scanning.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1518.001Security Software DiscoverySub-technique

Remsec has a plugin detect security products via active drivers.CitationKaspersky ProjectSauron Technical Analysis

EnterpriseT1071.004DNSSub-technique

Remsec is capable of using DNS for C2.CitationSymantec Remsec IOCsCitationKaspersky ProjectSauron Full ReportCitationKaspersky ProjectSauron Technical Analysis

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0041: Strider

Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.[1][2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.5
Created
Modified
Raw hash
c15f99ff2a8bc23b...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.5Current bundlec15f99ff2a8b…
19.11.5Older bundlec15f99ff2a8b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Symantec Strider Blog

    Symantec Security Response. (2016, August 7). Strider: Cyberespionage group turns eye of Sauron on targets. Retrieved August 17, 2016.

  2. [2]
    Kaspersky ProjectSauron Blog

    Kaspersky Lab's Global Research & Analysis Team. (2016, August 8). ProjectSauron: top level cyber-espionage platform covertly extracts encrypted government comms. Retrieved August 17, 2016.

    Open source URL
  3. [3]
    ProjectSauron

    ProjectSauron is used to refer both to the threat group also known as G0041 as well as the malware platform also known as S0125. (Citation: Kaspersky ProjectSauron Blog)

  4. [4]
    mitre-attackS0125
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.