'SteelFox' Malware Blitz Infects 11K Victims With Bundle of Pain
ID: 88313f0c-ddd2-5661-a42e-b1e11d1c440d
STIX ID: report--88313f0c-ddd2-5661-a42e-b1e11d1c440d
Feed Name: Dark Reading
Kaspersky researchers uncovered "SteelFox", a mass-distribution malware bundle active since at least February 2023 that masquerades as application activators (e.g., AutoCAD, JetBrains, Foxit). The dropper installs a 64-bit Windows payload that deploys a modified XMRig cryptominer and a data stealer which harvests browser data, credentials, system and network information; the campaign has compromised more than 11,000 victims across multiple countries and leverages advanced evasion and persistence techniques including encrypted initial stages, timestamp/junk-data modification, Windows service-based execution, SSL pinning, and TLS 1.3-protected C2 traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
