StrelaStealer

MITRE ATT&CK: S1183 View on attack.mitre.org

Aliases: StrelaStealer

First seen
2022-11-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
2485 (1388 malicious)
Last IoC activity
2026-09-02 03:36:27
Profile updated
2026-07-07 13:16:09

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

StrelaStealer is an information stealer malware variant first identified in November 2022 and active through late 2024. StrelaStealer focuses on the automated identification, collection, and exfiltration of email credentials from email clients such as Outlook and Thunderbird.

Recent IoC activity

1,391 malicious indicators in Maltiverse are attributed to StrelaStealer (S1183). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname steepdvapeco.com 2026-09-03 1
hostname gershpatrick.com 2026-09-03 2
hostname gotthilft.de 2026-09-03 1
hostname horlogescomtoises.fr 2026-09-03 1
hostname croydoncommunitychurch.org 2026-09-03 2
hostname novacare.be 2026-09-03 2
hostname monalisadebatom.com.br 2026-09-03 1
hostname opcina-kljuc.ba 2026-09-03 1
hostname landscapesnaturally.co.uk 2026-09-03 1
hostname natureorganicbeauty.com 2026-09-03 1
hostname eyelashmakeupartist.com 2026-09-03 1
hostname tylebongda.net 2026-09-03 1
hostname nindica.com 2026-09-03 1
hostname shesays.business 2026-09-03 1
hostname roulettespel.info 2026-09-03 1
hostname derdoc.com 2026-09-03 1
hostname apartmani-majda.eu 2026-09-03 1
hostname prodaja.niz.ba 2026-09-03 1
hostname mail.theunconventionalplaybook.com 2026-09-03 1
hostname internetmarketingdothisnotthat.com 2026-09-03 1

Detection coverage

  • 1 YARA rules
  • 743 Sigma rules

Malware & tools used

  • Data Obfuscation (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Web Protocols (attack-pattern)
  • Debugger Evasion (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Code Signing (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Rename Legitimate Utilities (attack-pattern)
  • Malicious File (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • JavaScript (attack-pattern)
  • Rundll32 (attack-pattern)
  • Software Discovery (attack-pattern)
  • Software Packing (attack-pattern)
  • PowerShell (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Virtualization/Sandbox Evasion (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Compression (attack-pattern)
  • Credentials in Registry (attack-pattern)
  • Masquerading (attack-pattern)
  • Standard Encoding (attack-pattern)
  • DLL (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)

Detection rules

  • MALPEDIA_Win_Strelastealer_Auto (yara-rule)

Reports & references

  • ibm.com — Strela Stealer Todays Invoice Tomorrows Phish (report)
  • cip.gov.ua — Download (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Strelastealer (report)
  • trustwave.com — Proton66 Part 2 Compromised Wordpress Pages And Malware Campaigns (report)
  • blog.sonicwall.com — Strelastealer Resurgence Tracking A Javascript Driven Credential Stealer Targeting Europe (report)
  • Palo Alto Unit 42 — Strelastealer Campaign (report)
  • blog.sonicwall.com — Updated Strelastealer Targeting European Countries (report)
  • logpoint.com — Strela A Newcomer In Stealer Family (report)
  • cert-agid.gov.it — Analisi Tecnica E Considerazioni Sul Malware Strela (report)
  • medium.com — Shortandmalicious Strelastealer Aims For Mail Credentials A4C3E78C8Abc (report)
  • aryaka.com — Strela Stealer Malware Analysis (report)
  • blogs.infoblox.com — Detour Dog Dns Malware Powers Strela Stealer Campaigns (report)
  • research.openanalysis.net — Streala (report)
  • MITRE ATT&CK — S1183 (report)
  • fortgale.com — Strelastealer Malware Analysis 2 (report)
  • securityintelligence.com — Strela Stealer Todays Invoice Tomorrows Phish (report)

External references