logo

Kaspersky Labs Uncovers SteelFox Trojan: 11,000+ Devices Infected

ID: 6815968d-c3ec-592a-91b3-dca48840079d

STIX ID: report--6815968d-c3ec-592a-91b3-dca48840079d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-11-07

Date Updated: 2026-04-22

Author: do son

...
...

Kaspersky researchers discovered SteelFox, a trojan distributed through forum posts and malicious torrents disguised as software activators. Once granted administrative privileges it installs stealthily, abuses an outdated driver (WinRing0.sys) to escalate privileges, and performs data theft from multiple browsers and system profiling while running a modified XMRig miner. The malware employs AES-128 payload encryption, DoH for dynamic IP changes, and SSL pinning to evade detection, and has infected over 11,000 devices across multiple countries. Kaspersky recommends using trusted software sources, avoiding free activators, and keeping security solutions and privileges tightly controlled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.