Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool

2026-03-04T22:48:28Z1012e4b720f6078a67a5f3f8f9f780fa444a2e763b9da2a67e21dbc47ff45488
AI_augmented_attacksCISACisco_SD-WANClaude_CodeFortiGateLazarusMedusaNorth_KoreaOpenClawRATShinyHuntersSolarWinds_Serv-USteaeliteUNC2814credential_theftcryptostealerdata_breachdouble_extortionfirewall_compromisehardcoded_credentialsnpm_compromiseransomwareremote_code_executionsocial_engineeringsupply_chain_attack

What happened

A broad set of active and emerging threats was reported across multiple sectors. A new commodity RAT called Steaelite bundles credential and cryptocurrency stealers, live surveillance, and ransomware to facilitate double-extortion campaigns. Nation-state and state-linked activity includes suspected North Korean backdoors targeting US healthcare and education, and Lazarus Group adoption of Medusa ransomware. Multiple high-impact product vulnerabilities are being actively exploited or urgently warned about: a Five Eyes joint alert over Cisco Catalyst SD‑WAN bugs, four critical make-me-root flaws

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
1012e4b720f6078a67a5f3f8f9f780fa444a2e763b9da2a67e21dbc47ff45488
Enrichment time
2026-03-04T22:48:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool · Baitaphish