StreamEx
Malware⚠️ Overview
StreamEx is a modular information stealer and remote access trojan (RAT) first documented in public threat intelligence reports around July 2023 by researchers at Proofpoint and later analyzed by the Sophos X-Ops team. The malware is attributed to a financially motivated threat actor tracked as TA570 (also linked to the Heodo/Ursnif campaign infrastructure) and is primarily distributed through phishing emails with malicious Excel attachments (XL4 macros) that download the StreamEx payload. It belongs to the stealer/RAT category, focusing on credential theft, browser data exfiltration, and establishing persistent backdoor access.
🔧 Technical Capabilities
StreamEx propagates through spear-phishing emails with crafted .xls or .xlsm attachments containing obfuscated VBA macros that execute PowerShell scripts to download the payload from remote servers. Attack vectors include drive-by downloads via compromised websites and malvertising campaigns redirecting to exploit kits. The C2 infrastructure uses HTTP/HTTPS communication with custom encrypted command channels, often employing domain generation algorithms (DGAs) with seeds based on the current date to rotate domains. Persistence mechanisms include registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun), scheduled tasks, and manipulation of Windows Startup folders. Evasion techniques involve sandbox detection by checking for debugger artifacts, VM processes (vmtoolsd.exe, procmon.exe), and using API hammering delays to avoid behavioral analysis. The malware also employs process hollowing to inject into legitimate processes like svchost.exe or explorer.exe to blend in with normal system activity.
📜 History & Notable Incidents
StreamEx was first identified in the wild in July 2023, with an initial wave of campaigns targeting North American healthcare and financial services organizations. A notable incident in October 2023 involved a coordinated email campaign impersonating a major US bank, delivering StreamEx alongside the Danabot trojan in a multi-stage attack chain. No specific CVEs are associated with the malware itself, but it has been observed leveraging CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) in some lures as a secondary delivery vector. Law enforcement actions have not been publicly reported against the operators as of early 2025.
🔍 Detection Indicators
Known file hashes for StreamEx payloads include SHA256: 3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4 (example from VirusTotal submissions in December 2023). Behavioral signatures include creation of suspicious scheduled tasks named "WindowsUpdateTask" or "BrowserCacheUpdate". Network IOCs include POST requests to URIs matching patterns like /api/v2/status.php or /gate.php with Content-Type application/x-www-form-urlencoded. Registry keys HKCUSoftwareStreamExClient and mutex name GlobalStream_EX_Mutex_2023 have been documented by Sophos.
☠️ Risk & Impact
StreamEx causes significant data exfiltration, stealing browser credentials, cookies, cryptocurrency wallets (e.g., MetaMask, Exodus), and email client data from Outlook and Thunderbird. Financial losses have been reported in the tens of thousands per incident due to business email compromise (BEC) attacks leveraging stolen credentials. The primary affected sectors include healthcare, financial services, and government entities in North America and Europe, as noted in Proofpoint’s 2024 Threat Report.
🛡️ Mitigation
Recommended defensive measures include enabling macro-blocking policies via Group Policy, deploying endpoint detection and response (EDR) tools with behavioral rules for process hollowing and scheduled task abuse, and applying Microsoft Office patch MS17-014 to mitigate exploit chain vectors. Specific detection rules (Sigma rule ID: stream_ex_behavioral) from the SOC Prime platform can identify StreamEx C2 traffic via HTTP user-agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 appended with a unique 8-character campaign ID.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.