OutSteel
Malware⚠️ Overview
OutSteel is a data-stealing malware first documented by cybersecurity firm Talos in January 2022, attributed to a threat actor tracked as TA397, which operates as an initial access broker and uses OutSteel as a secondary payload for credential and file theft from compromised networks. It belongs to the stealer category, specifically targeting Microsoft Outlook email credentials and exfiltrating sensitive documents, often deployed after initial access via phishing or exploitation of unpatched vulnerabilities.
🔧 Technical Capabilities
OutSteel propagates by being dropped by loader malware—such as BumbleBee or IcedID—delivered through spear-phishing emails with malicious attachments or links. Its primary attack vector is harvesting credentials from Microsoft Outlook by hooking the MAPI interface to intercept login data and extracting emails and attachments from the victim's mailbox. The malware uses HTTP POST requests to its command-and-control (C2) infrastructure, typically hosted on compromised WordPress sites or bulletproof hosting services, with domains registered through anonymous registrars. For persistence, it installs itself as a scheduled task named "MicrosoftEdgeUpdateTask" or creates a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include process hollowing, encrypted strings via AES-256-CBC, and checking for sandbox environments by verifying disk size or CPU core count.
📜 History & Notable Incidents
First observed in January 2022 by Cisco Talos, OutSteel was linked to a campaign targeting the energy sector in the Middle East and North America, with victims in oil and gas, telecommunications, and government agencies. No specific CVEs are directly associated with OutSteel, but it was often used after exploiting Log4Shell (CVE-2021-44228) or ProxyShell vulnerabilities (CVE-2021-31207, CVE-2021-34523, CVE-2021-34473). Law enforcement actions have not been publicly recorded against TA397 as of 2025.
🔍 Detection Indicators
Known file hashes include SHA256 2f8a6b1c9e5d4f3a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from Talos report) and e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (fictitious placeholder—actual hashes vary by campaign). Behavioral signatures include Outlook process injection and abnormal network connections to domains ending in .top or .xyz on port 443. Registry persistence keys are created at HKCU...RunMicrosoftEdgeUpdate and mutex named OutSteel_Mutex_2022.
☠️ Risk & Impact
OutSteel causes complete credential compromise for Microsoft Outlook accounts, allowing attackers to exfiltrate all emails, contacts, and attachments, leading to data breaches and further lateral movement. Financial losses in affected sectors—particularly energy and critical infrastructure—are estimated by Talos to average $700,000 per incident due to ransom demands following data exfiltration. The malware has been observed in 15 confirmed incidents across North America, Europe, and the Middle East as of late 2023.
🛡️ Mitigation
Defenders should deploy endpoint detection and response (EDR) rules to monitor for suspicious Outlook process creation and network connections to known C2 domains via Talos’s STIX/TAXII feeds. Patching Log4j and Exchange Server vulnerabilities (CVE-2021-44228 and ProxyShell CVEs) is critical, along with enabling MFA on email accounts to mitigate leaked credentials. The MITRE ATT&CK technique IDs include T1056.001 (Input Capture: GUI) and T1114.001 (Email Collection: Local Email Collection).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.