Netskope Threat Labs

StrelaStealer

ATP Sandbox Adv. HeuristicsAVNetskope IPS

StrelaStealer is an information stealer that targets email credentials, harvesting saved passwords from Outlook, Thunderbird, and browsers on infected systems. Its operators deliver it through phishing campaigns that hit organizations across Europe and North America, and stolen email access fuels invoice fraud and further phishing. Because compromised mailboxes enable business email compromise, detections warrant immediate credential resets and mailbox audits.

First seen
August 2023
Last seen
October 2026
Strelastealer

34 techniques across 9 tactics.

TA0001 Initial Access

TA0002 Execution

TA0005 Stealth

TA0006 Credential Access

TA0007 Discovery

  • T1082System Information Discovery
  • T1518Software Discovery
  • T1614System Location Discovery

TA0009 Collection

  • T1119Automated Collection

TA0011 Command and Control

TA0010 Exfiltration

  • T1020Automated Exfiltration
  • T1041Exfiltration Over C2 Channel

TA0112 Defense Impairment

Alert Name
Document-Office.Downloader.StrelaStealer
Document-Word.Trojan.StrelaStealer
Email-MIME.Trojan.Strelastealer
Email-MIME.Trojan.StrelaStealer
GT:JS.StrelaStealer.2.0057ACE1
GT:JS.StrelaStealer.2.016737FF
GT:JS.StrelaStealer.2.01A6775E
GT:JS.StrelaStealer.2.020A7D1E
GT:JS.StrelaStealer.2.024339F5
GT:JS.StrelaStealer.2.02654451