TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
How to Repurpose Old Keyboards as macOS Shortcut Macropads
Google Keep leaves Apple Watch users without quick notes
Apple’s Siri Rescue Plan: Outsourcing AI to OpenAI or Anthropic After Years of Struggle
AI Arms Race Heats Up as Meta Unveils Superintelligence Labs
How to Find Your Most-Played Songs of All Time on Apple Music
Wednesday, Jul 2, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Malware Spares Russian Systems in Recent Attacks
The Tech Basic > News > Malware Spares Russian Systems in Recent Attacks
News

Malware Spares Russian Systems in Recent Attacks

Evelyn Blake
Last updated: 25 June 2024 19:59
Evelyn Blake
Share
SHARE

Security researchers at Sonicwall have noticed a significant rise in infections caused by the Strelastealer malware, a well-known infostealer. The malware is designed to steal access data specifically from Outlook and Thunderbird. The targets of this campaign are users located in Germany and three other European Union countries, excluding Russia.

Contents
Russian Systems Remain UnaffectedStrelastealer Has Been Active Since At Least The End Of 2022

Please follow us on Twitter and Facebook

The infection chain observed by Sonicwall researchers does not differ from previous attacks involving Strelastealer. However, the attackers have recently implemented a check to prevent infections on systems based in Russia.

The attack campaign, as monitored by Sonicwall, focuses on specific regions within the EU: Poland, Spain, Italy, and Germany. The attackers aim to obtain login information from Outlook and Thunderbird email programs, primarily on Windows operating systems.

According to the researchers, the attacks commence with emails containing archive files containing obfuscated JavaScript. Upon execution of the file, the system’s language is checked initially.

Read Also: Reportedly, Kaspersky’s AI Used in Russian Military Drones

Russian Systems Remain Unaffected

Malware Spares Russian Systems in Recent Attacks (1)

If the language code detected is Russian, the infection process stops. Otherwise, Strelastealer proceeds to install using a DLL file containing “highly obfuscated code”.

To identify the origin of the targeted system, the malware uses an API called GetKeyboardLayout to check the selected keyboard language. Sonicwall explains that the malware compares this with several language codes commonly used in Spanish, Polish, Italian, and German systems.

Afterwards, the attackers search through the user’s Appdata directory and the Windows registry to locate user profiles associated with Thunderbird and Outlook. Any discovered data is then transmitted to a server controlled by the attackers.

Read Also: US Wants to Prevent China and Russia from Using Advanced Software to Develop AI

Strelastealer Has Been Active Since At Least The End Of 2022

The researchers did not clarify the method by which attackers convince their victims to open the archive file attached to the emails, initiating the infection process. It’s possible they employ social engineering tactics, potentially leveraging information about the target person obtained from data breaches or other forms of contact.

In early April, Sonicwall researchers released a detailed report on Strelastealer, providing additional technical insights into the malware. The initial instances of attacks involving this malware were detected in November 2022.

Read Also: Russia Carries Out Cyber Attacks on German Facilities

Share This Article
Facebook Reddit Copy Link Print
Share
Evelyn Blake
By Evelyn Blake
Follow:
Evelyn Blake is an investor in technology and journalist who has been in the nascent space since 2014. Her love and passion for technological innovations made her delve deeper into the world of technology evolution. As a journalist, Evelyn has been covering latest trends and emerging gadgetries. She is a philanthropist and human rights activist.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

macOS

How to Repurpose Old Keyboards as macOS Shortcut Macropads

Salman Akhtar
Apple Watch

Google Keep leaves Apple Watch users without quick notes

Salman Akhtar
Apple Siri

Apple’s Siri Rescue Plan: Outsourcing AI to OpenAI or Anthropic After Years of Struggle

Salman Akhtar
Meta

AI Arms Race Heats Up as Meta Unveils Superintelligence Labs

Salman Akhtar

You Might Also Like

Apple Music
News

How to Find Your Most-Played Songs of All Time on Apple Music

MacBook with A18 Pro
News

MacBook with A18 Pro Chip Spotted in macOS 15 Code

Spotify
News

Spotify Gives Discover Weekly More Control With New Genre Picks

Apple Vision Pro
GadgetNews

Apple Vision Pro M5 Chip: 2025 Launch, Roadmap Details

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
YouTube Raises Livestream Age to 16: New 2025 Rules
Nvidia RTX 50 Super Leak: Up to 24 GB VRAM and 415 W TGP
Samsung Tri Fold Phone Rumored to Debut in July with October Release
Meta Eyes PlayAI Acquisition for Voice Cloning Technology
How TikTok’s Bulletin Boards Will Change Brand Engagement

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?