DCSO CyTec Blog. (2022, November 8). #ShortAndMalicious: StrelaStealer aims for mail credentials. Retrieved December 31, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1001 Data Obfuscation |
MalwareStrelaStealer | StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload. |
| T1020 Automated Exfiltration |
MalwareStrelaStealer | StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1027 Obfuscated Files or Information |
MalwareStrelaStealer | StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1027.013 Encrypted/Encoded File |
MalwareStrelaStealer | StrelaStealer uses XOR-encoded strings to obfuscate items. |
| T1036.003 Rename Legitimate Utilities |
MalwareStrelaStealer | StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation. |
| T1036.008 Masquerade File Type |
MalwareStrelaStealer | StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrelaStealer | StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1071.001 Web Protocols |
MalwareStrelaStealer | StrelaStealer communicates externally via HTTP POST with encrypted content. |
| T1119 Automated Collection |
MalwareStrelaStealer | StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareStrelaStealer | StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file. |
| T1204.002 Malicious File |
MalwareStrelaStealer | StrelaStealer relies on user execution of a malicious file for installation. |
| T1552.001 Credentials In Files |
MalwareStrelaStealer | StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application. |
| T1552.002 Credentials in Registry |
MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| T1566.001 Spearphishing Attachment |
MalwareStrelaStealer | StrelaStealer has been distributed as a spearphishing attachment. |
| T1574.001 DLL |
MalwareStrelaStealer | StrelaStealer has sideloaded a DLL payload using a renamed, legitimate `msinfo32.exe` executable. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.