logo

'SteelFox' Malware Blitz Infects 11K Victims With Bundle of Pain

ID: 88313f0c-ddd2-5661-a42e-b1e11d1c440d

STIX ID: report--88313f0c-ddd2-5661-a42e-b1e11d1c440d

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-11-07

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Kaspersky researchers uncovered "SteelFox", a mass-distribution malware bundle active since at least February 2023 that masquerades as application activators (e.g., AutoCAD, JetBrains, Foxit). The dropper installs a 64-bit Windows payload that deploys a modified XMRig cryptominer and a data stealer which harvests browser data, credentials, system and network information; the campaign has compromised more than 11,000 victims across multiple countries and leverages advanced evasion and persistence techniques including encrypted initial stages, timestamp/junk-data modification, Windows service-based execution, SSL pinning, and TLS 1.3-protected C2 traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.