Steaelite RAT Fuels New Wave of Double Extortion Threats Targeting Enterprises
The emergence of a new remote access trojan (RAT) named Steaelite has raised significant concerns among enterprise security teams. Initially detected in underground cybercrime forums in November 2025, this malware integrates data theft and ransomware…
The emergence of a new remote access trojan (RAT) named Steaelite has raised significant concerns among enterprise security teams. Initially detected in underground cybercrime forums in November 2025, this malware integrates data theft and ransomware deployment into a single browser-based control panel.
Steaelite is marketed on dark web platforms as a "fully undetectable" (FUD) RAT compatible with Windows 10 and 11, featuring Hidden Virtual Network Computing (HVNC) monitoring and banking application bypass capabilities. The tool has gained attention with over 87 messages across various forum threads.
BlackFog analysts have highlighted Steaelite as a significant threat due to its integration of the double extortion attack chain into one web panel. It simplifies the process for low-skilled cybercriminals, allowing them to conduct extortion operations independently.
Furthermore, the tool's developer has announced an Android ransomware module, indicating potential expansion to mobile devices used for two-factor authentication and business messaging, thus broadening the attack surface for targeted enterprises.
Steaelite's browser-based operator dashboard automates the harvesting of browser-stored passwords, session cookies, and application tokens upon a victim's connection. The primary toolbar offers functionalities such as:
Remote code execution Live screen streaming Webcam and microphone access File management Process control Clipboard monitoring Password recovery Location tracking DDoS modules VB.NET payload compilation
The emergence of a new remote access trojan (RAT) named Steaelite has raised significant concerns among enterprise security teams.
The advanced tools section includes ransomware deployment, hidden RDP, Windows Defender disabling, and persistence installation, enabling full machine control with minimal effort.
A cryptocurrency clipper feature in the developer tools panel silently monitors the victim's clipboard, swapping cryptocurrency wallet addresses with those controlled by the attacker, thus redirecting funds without the victim's awareness.
IOC Type Value
SHA-256 b2a8d97da2a653de75d3d1be5839
C2 1e81ea2a059f.ngrok-free.app
Associated Paths /dashboard.html, /victim.html
Username Steaelite
First Observed November 2025
Organizations are advised to monitor outbound network traffic for unusual data transfers, enforce application whitelisting, and apply endpoint detection rules that flag HVNC activity and unexpected UAC bypass attempts. Regular auditing of browser-stored credentials and deploying phishing-resistant multi-factor authentication can mitigate the impact of automated credential harvesting.
Based on reporting by Cyber Security News.
