Large-Scale StrelaStealer Campaign in Early 2024
ID: 5dc43333-c2e2-5f6a-b4a2-2dcab7b863ff
STIX ID: report--5dc43333-c2e2-5f6a-b4a2-2dcab7b863ff
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-03-22
Date Updated: 2026-04-28
Author: Benjamin Chang, Goutam Tripathy, Pranay Kumar Chhaparwal, Anmol Maurya and Vishwa Thothathri
StrelaStealer is an active email credential stealer used in large-scale EU and U.S. spam campaigns; recent variants deliver a zipped JScript that decodes a Base64 payload into a DLL (executed via rundll32), and the payload now employs control-flow obfuscation and other evasion techniques. The report includes campaign timelines, affected industries, technical analysis of the updated packer and payload, IOCs (hashes, C2 IP), and Palo Alto Networks detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
