Over 100 US and EU orgs targeted in StrelaStealer malware attacks
ID: 2e4ab865-9299-5bed-b0af-9e85aba0d57b
STIX ID: report--2e4ab865-9299-5bed-b0af-9e85aba0d57b
Feed Name: Bleeping Computer
StrelaStealer, an email-credential-stealing infostealer first seen in 2022, is the subject of a large-scale phishing campaign that has impacted over a hundred organizations across the United States and Europe; Unit42 observed heightened distribution in late 2023 and a notable wave in early 2024. The campaign evolved from ISO/.lnk polyglot delivery to ZIP attachments that drop JScript which decodes and executes a DLL via rundll32, and the malware now employs control-flow obfuscation and removed PDB strings to hinder detection and analysis, while targeting sectors including high tech, finance, legal, government and energy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
