ATT&CKReferencesFortgale StrelaStealer 2023

Fortgale StrelaStealer 2023

Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.015
Compression
MalwareStrelaStealer

StrelaStealer has been delivered via JScript files in a ZIP archive.

T1027.016
Junk Code Insertion
MalwareStrelaStealer

StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1059.003
Windows Command Shell
MalwareStrelaStealer

StrelaStealer has included BAT files in some instances for installation.

T1059.007
JavaScript
MalwareStrelaStealer

StrelaStealer has been distributed as a malicious JavaScript object.

T1071.001
Web Protocols
MalwareStrelaStealer

StrelaStealer communicates externally via HTTP POST with encrypted content.

T1119
Automated Collection
MalwareStrelaStealer

StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution.

T1140
Deobfuscate/Decode Files or Information
MalwareStrelaStealer

StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file.

T1480
Execution Guardrails
MalwareStrelaStealer

StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables.

T1480.002
Mutual Exclusion
MalwareStrelaStealer

StrelaStealer variants include the use of mutex values based on the victim system name to prevent reinfection.

T1497
Virtualization/Sandbox Evasion
MalwareStrelaStealer

StrelaStealer payloads have used control flow obfuscation techniques such as excessively long code blocks of mathematical instructions to defeat sandboxing and related analysis methods.

T1552.001
Credentials In Files
MalwareStrelaStealer

StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application.

T1552.002
Credentials in Registry
MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

T1614.001
System Language Discovery
MalwareStrelaStealer

StrelaStealer variants check system language settings via keyboard layout or similar mechanisms.

T1622
Debugger Evasion
MalwareStrelaStealer

StrelaStealer variants include functionality to identify and evade debuggers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.