ATT&CKReferencesIBM StrelaStealer 2024

IBM StrelaStealer 2024

Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1020
Automated Exfiltration
MalwareStrelaStealer

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1027
Obfuscated Files or Information
MalwareStrelaStealer

StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives.

T1036
Masquerading
MalwareStrelaStealer

StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`.

T1036.005
Match Legitimate Resource Name or Location
MalwareStrelaStealer

StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company.

T1036.008
Masquerade File Type
MalwareStrelaStealer

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1059.001
PowerShell
MalwareStrelaStealer

StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation.

T1059.003
Windows Command Shell
MalwareStrelaStealer

StrelaStealer has included BAT files in some instances for installation.

T1059.007
JavaScript
MalwareStrelaStealer

StrelaStealer has been distributed as a malicious JavaScript object.

T1071.001
Web Protocols
MalwareStrelaStealer

StrelaStealer communicates externally via HTTP POST with encrypted content.

T1082
System Information Discovery
MalwareStrelaStealer

StrelaStealer variants collect victim system information for exfiltration.

T1105
Ingress Tool Transfer
MalwareStrelaStealer

StrelaStealer installers have used obfuscated PowerShell scripts to retrieve follow-on payloads from WebDAV servers.

T1119
Automated Collection
MalwareStrelaStealer

StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution.

T1132.001
Standard Encoding
MalwareStrelaStealer

StrelaStealer utilizes a hard-coded XOR key to encrypt the content of HTTP POST requests to command and control infrastructure.

T1218.011
Rundll32
MalwareStrelaStealer

StrelaStealer DLL payloads have been executed via `rundll32.exe`.

T1480
Execution Guardrails
MalwareStrelaStealer

StrelaStealer variants only execute if the keyboard layout or language matches a set list of variables.

T1518
Software Discovery
MalwareStrelaStealer

StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines.

T1552.002
Credentials in Registry
MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

T1553.002
Code Signing
MalwareStrelaStealer

StrelaStealer variants have used valid code signing certificates.

T1614.001
System Language Discovery
MalwareStrelaStealer

StrelaStealer variants check system language settings via keyboard layout or similar mechanisms.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.