logo

Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool

ID: f62e5c21-e487-52fb-8717-77d256ae9164

STIX ID: report--f62e5c21-e487-52fb-8717-77d256ae9164

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-02-27

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Steaelite is a commercial remote access trojan observed for sale on cybercrime forums that bundles credential and cryptocurrency stealers, live surveillance, and integrated ransomware to enable double extortion on Windows (with an Android module reportedly in development). Its browser-based dashboard automatically harvests browser-stored passwords, cookies, and tokens on connection and exposes modules for remote code execution, file management, live streaming, webcam/microphone access, clipboard clipping (wallet address swapping), Defender disabling, persistence, and ransomware deployment — effectively consolidating initial access, data exfiltration, and encryption capabilities into a single tool.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.