Steaelite RAT Fuels New Wave of Double Extortion Threats Targeting Enterprises
ID: 0196e657-2eeb-5eca-bbfd-8d036e6e88ee
STIX ID: report--0196e657-2eeb-5eca-bbfd-8d036e6e88ee
Feed Name: cybersecurityNews.com
Steaelite is a newly emerged commercial Windows remote access trojan (RAT) that consolidates automated credential and file exfiltration with built-in ransomware deployment into a single browser-based operator dashboard, lowering the skill required for double extortion attacks; features include HVNC, UAC bypass, clipboard cryptocurrency clipping, automated harvesting of browser-stored credentials and tokens, file manager/exfiltration, and a forthcoming Android ransomware module. The report includes observed IOCs (SHA-256, ngrok C2, associated paths), screenshots of the control panel, and mitigation recommendations such as monitoring outbound traffic, application whitelisting, endpoint detection rules for HVNC/UAC bypass, and phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
