Malware.View on attack.mitre.org
StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024. StrelaStealer focuses on the automated identification, collection, and exfiltration of email credentials from email clients such as Outlook and Thunderbird.
| Technique | Procedure example |
|---|---|
| T1001 Data Obfuscation |
StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload. |
| T1020 Automated Exfiltration |
StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST. |
| T1027 Obfuscated Files or Information |
StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives. |
| T1027.002 Software Packing |
StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult. |
| T1027.013 Encrypted/Encoded File |
StrelaStealer uses XOR-encoded strings to obfuscate items. |
| T1027.015 Compression |
StrelaStealer has been delivered via JScript files in a ZIP archive. |
| T1027.016 Junk Code Insertion |
StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes. |
| T1036 Masquerading |
StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`. |
| T1036.003 Rename Legitimate Utilities |
StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation. |
| T1036.005 Match Legitimate Resource Name or Location |
StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company. |
| T1036.008 Masquerade File Type |
StrelaStealer has been distributed as a DLL/HTML polyglot file. |
| T1041 Exfiltration Over C2 Channel |
StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers. |
| T1059.001 PowerShell |
StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation. |
| T1059.003 Windows Command Shell |
StrelaStealer has included BAT files in some instances for installation. |
| T1059.007 JavaScript |
StrelaStealer has been distributed as a malicious JavaScript object. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.