Researchers detailed StrelaStealer, an email-focused credential theft malware active since at least late 2022, that steals account data and mailbox information from Microsoft Outlook and Mozilla Thunderbird. The malware has been observed in campaigns affecting victims in Italy and appears to favor Spanish-speaking targets based on lure content and error messages. Analysis indicates the same actor likely develops and operates the malware, with the codebase evolving from DLL-based samples with encrypted strings to newer signed PE variants, including both 32-bit and 64-bit builds.
Technical analysis showed the delivery component uses a more sophisticated packer with control-flow obfuscation and hides an XOR-encoded PE payload in the .data section using a 20-byte rolling XOR key. Once launched, Strela enforces single-instance execution with a mutex, harvests Thunderbird and Outlook credentials, shows a decoy error to the victim, and exfiltrates data over HTTP POST to hard-coded command-and-control endpoints including 91.215.85.209/server.php and 193.106.191.166/server.php. Investigators also found evidence that the server validates submitted Thunderbird data, including JSON and SQLite content, suggesting the stolen information is actively processed rather than simply collected.

Pull IOCs and campaign context straight into your stack.
9 events from the most recent confirmed update back to the earliest known activity.
Logpoint analyzed StrelaStealer samples delivered via malspam ZIP archives containing an obfuscated JavaScript file that ran through wscript.exe, launched PowerShell, mapped a WebDAV share at 94.159.113.79:8888, and executed a remote DLL via regsvr32.exe or rundll32.exe. The analysis documented newer anti-analysis and obfuscation techniques in Strela's initial payload chain.
By mid-2024, IBM reported Strela Stealer had expanded beyond stealing Outlook and Thunderbird credentials to also collect system metadata and application inventories. The added data collection indicated a shift toward broader host reconnaissance alongside credential theft.
An April 2023 StrelaStealer sample switched from a DLL to a PE executable, left most strings in plaintext, used 91.215.85.209/server.php for C2, and replaced the PDF decoy with a Spanish error message box.
OSINT cited by CERT-AGID indicated the ASN hosting Strela infrastructure had also hosted command-and-control servers for other malware campaigns since early 2023.
CERT-AGID reported that Strela's C2 infrastructure appeared associated with a company named Prospero that was registered in November 2022.
A November 2022 StrelaStealer sample used XOR-encrypted strings, harvested IMAP and Microsoft Office-related data, and exfiltrated stolen information to 193.106.191.166/server.php. The sample also relied on a pre-positioned x.pdf decoy opened with Microsoft Edge.
Public malware repository pivots from Strela PDB paths identified a related sample dated 2022-01-23, indicating the developer had been working on similar projects by that time.
Aryaka published technical analysis of a StrelaStealer infection chain in which a ZIP-delivered obfuscated JavaScript launched PowerShell, fetched a decoy PDF from 193.143.1.205/invoice.php, retrieved a malicious DLL via WebDAV requests, and exfiltrated stolen data to 193.143.1.205 over HTTP POST. The report also documented detection artifacts including OPTIONS/PROPFIND/PROPPATCH usage, the Translate: f header, changing user-agent strings, and theft of browser, Thunderbird, and Outlook data.
CERT-AGID reported that a Strela malware campaign had been observed in Italy the previous week, targeting Thunderbird and Outlook credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 26 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
aryaka.com
Open sourceibm.com
Open sourcelogpoint.com
Open sourcecert-agid.gov.it
Open sourceresearch.openanalysis.net
Open sourcejscrambler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.