This new cybercrime campaign is after your Outlook email logins

A laptop showing lots of email notifications
(Image credit: Shutterstock)

Researchers have discovered a new malicious campaign going after user's email login credentials. 

Cybersecurity experts from DSCO CyTec found an infostealer dubbed “StrelaStealer” being actively used to steal login credentials from Spanish-speaking Outlook and Thunderbird email client users.

The campaign has only just been observed for the first time, suggesting it might be relatively new, and as such, possibly more dangerous until experts unravel its inner workings.

Polyglot files

The attacks start much the same as other campaigns - with a phishing email. 

So far, the researchers discovered two different email campaigns, one distributing an ISO with a “msinfo32.exe” executable file, which sideloads the bundled malware via DLL order hijacking. The second one, arguably more interesting, shares two files in the ISO - a Factura.lnk shortcut file, and an x.html browser document.

The latter was subsequently found to be a polyglot file - a file that can be treated as different formats, depending on the app that opens it. 

So when the victim runs the shortcut file, it will run the HTML file twice - once as a DLL that loads the StrelaStealer, and once as an HTML file, which opens a decoy document in the browser. That way, the victim doesn’t suspect that a malicious file was loaded in the background. 

Unlike most infostealers, which strive to grab as much intel as they can from the target endpoint, StrelaStealer is a unique beast, as it only goes after email login credentials. 

For Thunderbird users, the malware will search the %APPDATA%\Thunderbird\Profiles\' directory for 'logins.json' and 'key4.db'. Should it find them, it exfiltrates them to the C2 server. For Outlook users, the malware will read the Windows Registry to find the software’s key, and then locate the IMAP User, IMAP Server, and IMAP Password values to exfiltrate. 

So far, the malware has only targeted the Spanish-speaking community, prompting the media to speculate that it’s being used in highly targeted attacks.  

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Illustration of a laptop with a magnifying glass exposing a beetle on-screen
Microsoft Outlook targeted by new malware attacks allowing sneaky hijacking
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
A fresh Samsung Galaxy S25 Edge leak hints at a 2K display and a titanium frame
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited