New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.
ID: a5983bf8-5407-5e5a-9eb9-3c478c55426c
STIX ID: report--a5983bf8-5407-5e5a-9eb9-3c478c55426c
Feed Name: The Hacker News
Cybersecurity researchers have observed multiple phishing campaigns delivering an evolving information stealer named StrelaStealer to over 100 organizations in the EU and U.S.; attackers vary initial attachment formats and use ZIP archives containing JavaScript that drops a batch file to launch an obfuscated DLL via rundll32.exe. The report highlights improved obfuscation and anti-analysis techniques in newer StrelaStealer variants, links to other commodity malware distributed via services like AceCryptor and PrivateLoader (including Stealc and Rescoms), and describes related social-engineering scams and activity clusters (e.g., Fluffy Wolf) that illustrate widespread misuse of malware-as-a-service and low-skill but effective threat actor operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
