logo

New SteelFox malware hijacks Windows PCs using vulnerable driver

ID: e4575054-21c7-57eb-85d4-c0ed7c0ba4e6

STIX ID: report--e4575054-21c7-57eb-85d4-c0ed7c0ba4e6

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-11-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

SteelFox is a criminal malware bundle distributed via cracked software on forums and torrent sites that installs a modified XMRig miner and an info-stealer; it escalates to NT/SYSTEM by deploying the vulnerable WinRing0.sys driver (CVE-2020-14979, CVE-2021-41285), communicates with hardened C2 (SSL pinning, TLS 1.3, DoH), and exfiltrates browser-stored data (including credit cards) and system/network information — Kaspersky observed it since Feb 2023 with detections across multiple countries and ~11,000 blocking events.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.