New SteelFox malware hijacks Windows PCs using vulnerable driver
ID: e4575054-21c7-57eb-85d4-c0ed7c0ba4e6
STIX ID: report--e4575054-21c7-57eb-85d4-c0ed7c0ba4e6
Feed Name: Bleeping Computer
SteelFox is a criminal malware bundle distributed via cracked software on forums and torrent sites that installs a modified XMRig miner and an info-stealer; it escalates to NT/SYSTEM by deploying the vulnerable WinRing0.sys driver (CVE-2020-14979, CVE-2021-41285), communicates with hardened C2 (SSL pinning, TLS 1.3, DoH), and exfiltrates browser-stored data (including credit cards) and system/network information — Kaspersky observed it since Feb 2023 with detections across multiple countries and ~11,000 blocking events.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
