Malicious emails purporting to be invoices that contain ZIP attachments have been delivered to facilitate the execution of a WebDAV-retrieved DLL that loads the updated Strela Stealer variant, which pilfers and exfiltrates Outlook and Thunderbird credentials, as well as system information, only after verifying devices located in Germany and Spain, according to an analysis from Cyble Research and Intelligence Labs. “The recent iterations of the Strela Stealer campaign reveal a notable advancement in malware delivery techniques, highlighting increased sophistication and stealth.
Source: SC Magazine