Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 2 actors

Strela Stealer

Strela Stealer is an information-stealing malware family focused on harvesting email client credentials, specifically from Microsoft Outlook and Mozilla Thunderbird. Reported theft includes Thunderbird credentials from %APPDATA%\Thunderbird\Profiles\logins.json and key4.db, and Outlook IMAP credentials from registry locations, with password decryption via CryptUnprotectData(). IBM X-Force reported exfiltration over HTTP POST to a hardcoded C2 endpoint at http://94.159.113[.]48/server.php, with repeated transmission attempts until a stop string such as "KH," "ANTIROK," or "CHOLLIMA" is received.

The malware is associated with the financially motivated threat actor Hive0145, which IBM assessed may be the sole operator and likely functions as an initial access broker. Campaigns have targeted victims across Europe since at least late 2022, with reporting specifically naming Spain, Germany, Ukraine, Austria, Liechtenstein, Luxembourg, and Switzerland. Trustwave SpiderLabs and IBM both described targeting of Outlook and Thunderbird users, and Proton66-hosted infrastructure was reported as being used to distribute Strela Stealer in early 2025.

Observed delivery is primarily phishing-based. Hive0145 used invoice and receipt lures, including authentic stolen invoice emails whose attachments were replaced with malicious payloads while preserving the original email content and filename pattern. Infection chains included archives containing heavily obfuscated JavaScript downloaders that retrieved and executed crypted Strela Stealer DLLs, often via WebDAV and rundll32.exe. Earlier campaigns used polyglot files, encrypted ZIP archives with per-email passwords, uncommon executable extensions such as .com and .pif, valid code-signing certificates, and a custom crypter/loader referred to as Stellar Crypter or Stellar Loader, which decrypts and executes the payload in memory. Recent variants reportedly added host profiling via systeminfo output and installed-application enumeration, along with expanded language and locale checks.

Strela Stealer has also been distributed through infrastructure operated by Detour Dog, which Infoblox described as a service provider or partner rather than the malware operator. Detour Dog used compromised WordPress sites, DNS TXT-record-based command and control, and a first-stage backdoor/reverse shell called StarFish to facilitate delivery. Infoblox reported Base64-encoded TXT responses containing the word "down" to trigger remote file execution behavior on infected sites, which then retrieved content from verified Strela Stealer C2 infrastructure. Spam delivery in these campaigns was linked to REM Proxy and Tofsee botnets, while Detour Dog hosted much of the first-stage infrastructure.

High-confidence infrastructure and indicators mentioned in the content include the Strela Stealer C2 endpoint 94.159.113[.]48/server.php, WebDAV delivery from 94.159.113.48:8888, and Detour Dog sinkholed C2 domains webdmonitor[.]io and aeroarrows[.]io associated with Strela-related delivery operations.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
detour_dog

A threat actor named Detour Dog has been outed as powering campaigns distributing an information stealer known as Strela Stealer.

via the hacker newsthehackernews.com
Hive0145

A threat actor named Detour Dog has been outed as powering campaigns distributing an information stealer known as Strela Stealer.

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

"Cybersecurity Training Programs Don’t Prevent Employees from Falling for Phishing Scams" ... "After sending 10 different types of phishing emails..."; "...servers... resolve multiple domains used for phishing purpose."; "...use of phishing and fake app stores..."; "...email attachment."

Credential Access

1 technique
T1555Credentials from Password StoresEvidence1

"...deploying Strela Stealer, an information-stealing tool that extracts email login credentials..."

Command and Control

1 technique
T1071.004DNSEvidence1

"Responses to TXT record queries are Base64-encoded... to trigger this new action... novel networked malware distribution model using DNS"

INDICATORS OF COMPROMISE

IOCs tracked for this family

6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app9 months ago
domain●●●●●●●●●●●●View more in app9 months ago
ip.v4●●●●●●●●●●●●View more in app2 years ago
ip.v4●●●●●●●●●●●●View more in app2 years ago
ip.v4●●●●●●●●●●●●View more in app2 years ago
uri●●●●●●●●●●●●View more in app2 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching6

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.