Kaspersky Labs Uncovers SteelFox Trojan: 11,000+ Devices Infected
ID: 6815968d-c3ec-592a-91b3-dca48840079d
STIX ID: report--6815968d-c3ec-592a-91b3-dca48840079d
Feed Name: securityonline.info
Kaspersky researchers discovered SteelFox, a trojan distributed through forum posts and malicious torrents disguised as software activators. Once granted administrative privileges it installs stealthily, abuses an outdated driver (WinRing0.sys) to escalate privileges, and performs data theft from multiple browsers and system profiling while running a modified XMRig miner. The malware employs AES-128 payload encryption, DoH for dynamic IP changes, and SSL pinning to evade detection, and has infected over 11,000 devices across multiple countries. Kaspersky recommends using trusted software sources, avoiding free activators, and keeping security solutions and privileges tightly controlled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
