BlackFog researchers reported a new Windows-focused remote access trojan, Steaelite, being marketed in cybercrime circles as a “fully undetectable” RAT that combines data theft and ransomware to support double-extortion operations. The malware is controlled from a browser-based centralized dashboard and is designed to begin stealing data immediately upon a victim connecting—automatically harvesting browser-stored passwords, session cookies, and application tokens before an operator issues commands. The operator panels expose a broad capability set including remote code execution, file and process management, live surveillance (webcam/microphone), credential recovery, clipboard monitoring, DDoS, and additional “advanced” functions such as ransomware deployment, hidden RDP, Windows Defender tampering (disabling/exclusions), persistence, UAC bypass, and a cryptocurrency “clipper” that swaps wallet addresses during copy/paste operations.
This item is not fluff because it provides specific threat intelligence on an emerging criminal tool and its operational model (RAT + ransomware + infostealing under one control plane). Other items in the set are largely weekly roundups, policy coverage, conference/event reporting, career/compensation news, or generic security guidance and do not materially add corroborating details about Steaelite beyond brief mentions in newsletter-style aggregation.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Security Affairs included Steaelite RAT in its Malware Newsletter Round 86, summarizing prior research that the malware enables double-extortion operations from a single management panel. This was a roundup mention rather than a new development in the Steaelite story.
Researchers at BlackFog reported a new commercially sold remote access trojan called Steaelite, describing it as malware designed to combine automated data theft with ransomware deployment for double-extortion attacks on Windows systems. Their findings detailed its centralized browser-based control panel and broad post-compromise capabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.