logo

Strela Stealer Targets Europe Stealthily Via WebDav

ID: d26e1ce1-c921-57fa-add7-5a37c03bde04

STIX ID: report--d26e1ce1-c921-57fa-add7-5a37c03bde04

Feed Name: Cyble Blog

Threat Score
72/100

Date Published: 2024-10-30

Date Updated: 2026-07-17

...
...

Strela Stealer is being distributed via spear-phishing ZIP attachments containing heavily obfuscated JavaScript that executes a base64-encoded PowerShell command to load a malicious DLL from a WebDAV server and run an infostealer in memory; the malware harvests Outlook and Thunderbird credentials, collects system information, and uses locale checks to target German and Spanish victims, with extensive IOCs and mitigation guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.