StrelaStealer
MITRE ATT&CK: S1183 View on attack.mitre.org
Aliases: StrelaStealer
- First seen
- 2022-11-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2485 (1388 malicious)
- Last IoC activity
- 2026-09-02 03:36:27
- Profile updated
- 2026-07-07 13:16:09
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024. StrelaStealer focuses on the automated identification, collection, and exfiltration of email credentials from email clients such as Outlook and Thunderbird.
Recent IoC activity
1,391 malicious indicators in Maltiverse are attributed to StrelaStealer (S1183). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | steepdvapeco.com | 2026-09-03 | 1 |
| hostname | gershpatrick.com | 2026-09-03 | 2 |
| hostname | gotthilft.de | 2026-09-03 | 1 |
| hostname | horlogescomtoises.fr | 2026-09-03 | 1 |
| hostname | croydoncommunitychurch.org | 2026-09-03 | 2 |
| hostname | novacare.be | 2026-09-03 | 2 |
| hostname | monalisadebatom.com.br | 2026-09-03 | 1 |
| hostname | opcina-kljuc.ba | 2026-09-03 | 1 |
| hostname | landscapesnaturally.co.uk | 2026-09-03 | 1 |
| hostname | natureorganicbeauty.com | 2026-09-03 | 1 |
| hostname | eyelashmakeupartist.com | 2026-09-03 | 1 |
| hostname | tylebongda.net | 2026-09-03 | 1 |
| hostname | nindica.com | 2026-09-03 | 1 |
| hostname | shesays.business | 2026-09-03 | 1 |
| hostname | roulettespel.info | 2026-09-03 | 1 |
| hostname | derdoc.com | 2026-09-03 | 1 |
| hostname | apartmani-majda.eu | 2026-09-03 | 1 |
| hostname | prodaja.niz.ba | 2026-09-03 | 1 |
| hostname | mail.theunconventionalplaybook.com | 2026-09-03 | 1 |
| hostname | internetmarketingdothisnotthat.com | 2026-09-03 | 1 |
Detection coverage
- 1 YARA rules
- 743 Sigma rules
Malware & tools used
- Data Obfuscation (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Web Protocols (attack-pattern)
- Debugger Evasion (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Code Signing (attack-pattern)
- Execution Guardrails (attack-pattern)
- Rename Legitimate Utilities (attack-pattern)
- Malicious File (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- JavaScript (attack-pattern)
- Rundll32 (attack-pattern)
- Software Discovery (attack-pattern)
- Software Packing (attack-pattern)
- PowerShell (attack-pattern)
- Windows Command Shell (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Compression (attack-pattern)
- Credentials in Registry (attack-pattern)
- Masquerading (attack-pattern)
- Standard Encoding (attack-pattern)
- DLL (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
Detection rules
- MALPEDIA_Win_Strelastealer_Auto (yara-rule)
Reports & references
- ibm.com — Strela Stealer Todays Invoice Tomorrows Phish (report)
- cip.gov.ua — Download (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Strelastealer (report)
- trustwave.com — Proton66 Part 2 Compromised Wordpress Pages And Malware Campaigns (report)
- blog.sonicwall.com — Strelastealer Resurgence Tracking A Javascript Driven Credential Stealer Targeting Europe (report)
- Palo Alto Unit 42 — Strelastealer Campaign (report)
- blog.sonicwall.com — Updated Strelastealer Targeting European Countries (report)
- logpoint.com — Strela A Newcomer In Stealer Family (report)
- cert-agid.gov.it — Analisi Tecnica E Considerazioni Sul Malware Strela (report)
- medium.com — Shortandmalicious Strelastealer Aims For Mail Credentials A4C3E78C8Abc (report)
- aryaka.com — Strela Stealer Malware Analysis (report)
- blogs.infoblox.com — Detour Dog Dns Malware Powers Strela Stealer Campaigns (report)
- research.openanalysis.net — Streala (report)
- MITRE ATT&CK — S1183 (report)
- fortgale.com — Strelastealer Malware Analysis 2 (report)
- securityintelligence.com — Strela Stealer Todays Invoice Tomorrows Phish (report)
External references
- mitre-attack — S1183
- PaloAlto StrelaStealer 2024
- DCSO StrelaStealer 2022
- Fortgale StrelaStealer 2023
- IBM StrelaStealer 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy