logo

New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.

ID: a5983bf8-5407-5e5a-9eb9-3c478c55426c

STIX ID: report--a5983bf8-5407-5e5a-9eb9-3c478c55426c

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-03-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers have observed multiple phishing campaigns delivering an evolving information stealer named StrelaStealer to over 100 organizations in the EU and U.S.; attackers vary initial attachment formats and use ZIP archives containing JavaScript that drops a batch file to launch an obfuscated DLL via rundll32.exe. The report highlights improved obfuscation and anti-analysis techniques in newer StrelaStealer variants, links to other commodity malware distributed via services like AceCryptor and PrivateLoader (including Stealc and Rescoms), and describes related social-engineering scams and activity clusters (e.g., Fluffy Wolf) that illustrate widespread misuse of malware-as-a-service and low-skill but effective threat actor operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.