ATT&CKReferencesPaloAlto StrelaStealer 2024

PaloAlto StrelaStealer 2024

Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareStrelaStealer

StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult.

T1027.015
Compression
MalwareStrelaStealer

StrelaStealer has been delivered via JScript files in a ZIP archive.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1059.007
JavaScript
MalwareStrelaStealer

StrelaStealer has been distributed as a malicious JavaScript object.

T1119
Automated Collection
MalwareStrelaStealer

StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution.

T1140
Deobfuscate/Decode Files or Information
MalwareStrelaStealer

StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file.

T1218.011
Rundll32
MalwareStrelaStealer

StrelaStealer DLL payloads have been executed via `rundll32.exe`.

T1497
Virtualization/Sandbox Evasion
MalwareStrelaStealer

StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.