Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1020 Automated Exfiltration |
MalwareStrelaStealer | StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1027 Obfuscated Files or Information |
MalwareStrelaStealer | StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1036 Masquerading |
MalwareStrelaStealer | StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareStrelaStealer | StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company. |
| T1036.008 Masquerade File Type |
MalwareStrelaStealer | StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1041 Exfiltration Over C2 Channel |
MalwareStrelaStealer | StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1059.001 PowerShell |
MalwareStrelaStealer | StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation. |
| T1059.003 Windows Command Shell |
MalwareStrelaStealer | StrelaStealer has included BAT files in some instances for installation. |
| T1059.007 JavaScript |
MalwareStrelaStealer | StrelaStealer has been distributed as a malicious JavaScript object. |
| T1071.001 Web Protocols |
MalwareStrelaStealer | StrelaStealer communicates externally via HTTP POST with encrypted content. |
| T1082 System Information Discovery |
MalwareStrelaStealer | StrelaStealer variants collect victim system information for exfiltration. |
| T1105 Ingress Tool Transfer |
MalwareStrelaStealer | StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers. |
| T1119 Automated Collection |
MalwareStrelaStealer | StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution. |
| T1132.001 Standard Encoding |
MalwareStrelaStealer | StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure. |
| T1218.011 Rundll32 |
MalwareStrelaStealer | StrelaStealer DLL payloads have been executed via `rundll32.exe`. |
| T1480 Execution Guardrails |
MalwareStrelaStealer | StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables. |
| T1518 Software Discovery |
MalwareStrelaStealer | StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines. |
| T1552.002 Credentials in Registry |
MalwareStrelaStealer | StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application. |
| T1553.002 Code Signing |
MalwareStrelaStealer | StrelaStealer variants have used valid code signing certificates. |
| T1614.001 System Language Discovery |
MalwareStrelaStealer | StrelaStealer variants check system language settings via keyboard layout or similar mechanisms. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.