ATT&CKSoftwareStrelaStealer

StrelaStealer

S1183

Malware.View on attack.mitre.org

About this malware

StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024. StrelaStealer focuses on the automated identification, collection, and exfiltration of email credentials from email clients such as Outlook and Thunderbird.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1001
Data Obfuscation

StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload.

T1020
Automated Exfiltration

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1027
Obfuscated Files or Information

StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives.

T1027.002
Software Packing

StrelaStealer variants have used packers to obfuscate payloads and make analysis more difficult.

T1027.013
Encrypted/Encoded File

StrelaStealer uses XOR-encoded strings to obfuscate items.

T1027.015
Compression

StrelaStealer has been delivered via JScript files in a ZIP archive.

T1027.016
Junk Code Insertion

StrelaStealer variants have included excessive mathematical functions padding the binary and slowing execution for anti-analysis and sandbox evasion purposes.

T1036
Masquerading

StrelaStealer PE executable payloads have used uncommon but legitimate extensions such as `.com` instead of `.exe`.

T1036.003
Rename Legitimate Utilities

StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation.

T1036.005
Match Legitimate Resource Name or Location

StrelaStealer payloads have tailored filenames to include names identical to the name of the targeted organization or company.

T1036.008
Masquerade File Type

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1041
Exfiltration Over C2 Channel

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1059.001
PowerShell

StrelaStealer variants have used PowerShell scripts to download or drop payloads, including obfuscated variants to connect to a WebDAV server to download and executed an encrypted DLL for installation.

T1059.003
Windows Command Shell

StrelaStealer has included BAT files in some instances for installation.

T1059.007
JavaScript

StrelaStealer has been distributed as a malicious JavaScript object.

View all 34 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References4

  1. DCSO StrelaStealer 2022 Open source
    DCSO CyTec Blog. (2022, November 8). #ShortAndMalicious: StrelaStealer aims for mail credentials. Retrieved December 31, 2024.
  2. Fortgale StrelaStealer 2023 Open source
    Fortgale. (2023, September 18). StrelaStealer Malware Analysis. Retrieved December 31, 2024.
  3. IBM StrelaStealer 2024 Open source
    Golo Mühr, Joe Fasulo & Charlotte Hammond, IBM X-Force. (2024, November 12). Strela Stealer: Today’s invoice is tomorrow’s phish. Retrieved December 31, 2024.
  4. PaloAlto StrelaStealer 2024 Open source
    Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya & Vishwa Thothathri, Palo Alto Networks. (2024, March 22). Large-Scale StrelaStealer Campaign in Early 2024. Retrieved December 31, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.