Strela Stealer Targets Europe Stealthily Via WebDav
ID: d26e1ce1-c921-57fa-add7-5a37c03bde04
STIX ID: report--d26e1ce1-c921-57fa-add7-5a37c03bde04
Feed Name: Cyble Blog
Threat Score
Strela Stealer is being distributed via spear-phishing ZIP attachments containing heavily obfuscated JavaScript that executes a base64-encoded PowerShell command to load a malicious DLL from a WebDAV server and run an infostealer in memory; the malware harvests Outlook and Thunderbird credentials, collects system information, and uses locale checks to target German and Spanish victims, with extensive IOCs and mitigation guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
