ATT&CKReferencesDCSO StrelaStealer 2022

DCSO StrelaStealer 2022

DCSO CyTec Blog. (2022, November 8). #ShortAndMalicious: StrelaStealer aims for mail credentials. Retrieved December 31, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1001
Data Obfuscation
MalwareStrelaStealer

StrelaStealer encrypts the payload of HTTP POST communications using the same XOR key used for the malware's DLL payload.

T1020
Automated Exfiltration
MalwareStrelaStealer

StrelaStealer automatically sends gathered email credentials following collection to command and control servers via HTTP POST.

T1027
Obfuscated Files or Information
MalwareStrelaStealer

StrelaStealer has been distributed in ISO archives. StrelaStealer has been delivered in encrypted, password-protected ZIP archives.

T1027.013
Encrypted/Encoded File
MalwareStrelaStealer

StrelaStealer uses XOR-encoded strings to obfuscate items.

T1036.003
Rename Legitimate Utilities
MalwareStrelaStealer

StrelaStealer has used a renamed, legitimate `msinfo32.exe` executable to sideload the StrelaStealer payload during initial installation.

T1036.008
Masquerade File Type
MalwareStrelaStealer

StrelaStealer has been distributed as a DLL/HTML polyglot file.

T1041
Exfiltration Over C2 Channel
MalwareStrelaStealer

StrelaStealer exfiltrates collected email credentials via HTTP POST to command and control servers.

T1071.001
Web Protocols
MalwareStrelaStealer

StrelaStealer communicates externally via HTTP POST with encrypted content.

T1119
Automated Collection
MalwareStrelaStealer

StrelaStealer attempts to identify and collect mail login data from Thunderbird and Outlook following execution.

T1140
Deobfuscate/Decode Files or Information
MalwareStrelaStealer

StrelaStealer payloads have included strings encrypted via XOR. StrelaStealer JavaScript payloads utilize Base64-encoded payloads that are decoded via certutil to create a malicious DLL file.

T1204.002
Malicious File
MalwareStrelaStealer

StrelaStealer relies on user execution of a malicious file for installation.

T1552.001
Credentials In Files
MalwareStrelaStealer

StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application.

T1552.002
Credentials in Registry
MalwareStrelaStealer

StrelaStealer enumerates the registry key `HKCU\SOFTWARE\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\` to identify the values for "IMAP User," "IMAP Server," and "IMAP Password" associated with the Outlook email application.

T1566.001
Spearphishing Attachment
MalwareStrelaStealer

StrelaStealer has been distributed as a spearphishing attachment.

T1574.001
DLL
MalwareStrelaStealer

StrelaStealer has sideloaded a DLL payload using a renamed, legitimate `msinfo32.exe` executable.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.