logo

Large-Scale StrelaStealer Campaign in Early 2024

ID: 5dc43333-c2e2-5f6a-b4a2-2dcab7b863ff

STIX ID: report--5dc43333-c2e2-5f6a-b4a2-2dcab7b863ff

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-03-22

Date Updated: 2026-04-28

Author: Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya and Vishwa Thothathri

...
...

StrelaStealer is an active email credential stealer used in large-scale EU and U.S. spam campaigns; recent variants deliver a zipped JScript that decodes a Base64 payload into a DLL (executed via rundll32), and the payload now employs control-flow obfuscation and other evasion techniques. The report includes campaign timelines, affected industries, technical analysis of the updated packer and payload, IOCs (hashes, C2 IP), and Palo Alto Networks detection/mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.