Strela Stealer is a Windows information-stealing malware family focused primarily on harvesting credentials and related data from email clients, especially Microsoft Outlook and Mozilla Thunderbird, and in some campaigns also from web browsers such as Chrome, Edge, and Firefox. It has been active since at least late 2022 and is closely associated with the financially motivated threat actor Hive0145, which has conducted sustained phishing operations across Europe, including targeting in Spain, Germany, Ukraine, Italy, and the DACH region. Reporting also links its distribution ecosystem to the Detour Dog infrastructure, which has used compromised WordPress sites, DNS-based delivery mechanisms, and the StarFish backdoor as part of multi-stage campaigns.
Observed delivery commonly relies on phishing and malspam using invoice-themed lures, often with archive attachments containing heavily obfuscated JavaScript. The script typically invokes PowerShell or similar native tooling to retrieve additional payloads, sometimes displaying a decoy document while staging the malware. Multiple campaigns have used attachment hijacking, in which authentic stolen business emails are resent with the original attachment replaced by a weaponized archive, increasing credibility and enabling further credential theft. Variants have also been delivered through compromised websites that redirect victims or support staged retrieval.
The payload is commonly a heavily obfuscated DLL executed through legitimate Windows utilities such as Regsvr32 or Rundll32, including retrieval over WebDAV in some campaigns. Strela Stealer employs packing, encrypted sections, anti-debugging logic, control-flow obfuscation, sandbox evasion, deceptive PE metadata, and in recent reporting process injection and fileless execution techniques to hinder analysis and detection. Some campaigns also used crypter or loader components, including Stellar Loader or Stellar Crypter, to decrypt and execute the stealer in memory.
Its core function is credential theft and data exfiltration. High-confidence reporting shows it extracts stored credentials and profile data from Outlook and Thunderbird, and some variants also collect browser-stored logins. More recent versions have additionally gathered host profiling information such as system metadata and installed application inventories, indicating expanded reconnaissance value beyond pure credential theft. Stolen data is encrypted and exfiltrated over HTTP to attacker-controlled infrastructure, and the malware has been observed using direct IP-based communications rather than domain resolution in some cases.
Strela Stealer is primarily used to obtain access that can support follow-on fraud, business email compromise, and resale of compromised accounts or footholds. Its operators have steadily improved localization, lure quality, and evasion tradecraft, making it a persistent credential-theft threat to organizations and users across Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hive0145’s activity began in late 2022 with basic phishing campaigns delivering Strela Stealer via malicious email attachments.
A threat actor named Detour Dog has been outed as powering campaigns distributing an information stealer known as Strela Stealer.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
In late 2023 and early 2024, Hive0145 incorporated polyglot files, valid code-signing certificates and new crypters like Stellar Loader to improve evasion.
This program often employs obfuscation, sandbox evasion, and process injection to avoid security software.
The DLL has a single export function, DllRegisterServer, which is invoked by the Regsvr32 utility.
This program often employs obfuscation, sandbox evasion, and process injection to avoid security software.
Strela Stealer was updated to collect system metadata and application inventories, signaling a shift toward more comprehensive reconnaissance alongside credential theft.
This program often employs obfuscation, sandbox evasion, and process injection to avoid security software.
Strela Stealer then transmits the stolen information to remote Command-and-Control (C&C) servers controlled by threat actors
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information-stealing malware delivered via phishing emails with ZIP/JavaScript attachments. It uses obfuscated JavaScript and PowerShell to retrieve a DLL payload from a WebDAV-enabled server, steals credentials and profile data from browsers and email clients such as Chrome, Edge, Firefox, Thunderbird, and Outlook, and exfiltrates the data over HTTP to C2 infrastructure. The sample described also uses anti-analysis and obfuscation techniques including packing, encrypted data sections, anti-debugging, control-flow flattening, sandbox evasion, process injection, encrypted transmission, and fileless execution techniques.
Infostealer malware distributed via DNS-based attacks, capable of stealing credentials and sensitive information from infected hosts. Delivered through compromised websites using DNS TXT records as covert C2 and payload delivery channels.
Information-stealing malware delivered via compromised WordPress sites, used to exfiltrate sensitive data from infected systems.
Stealer malware referenced as being used in campaigns powered by 'Detour Dog' DNS malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.