Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool
2026-03-04T22:48:28Z•1012e4b720f6078a67a5f3f8f9f780fa444a2e763b9da2a67e21dbc47ff45488
AI_augmented_attacksCISACisco_SD-WANClaude_CodeFortiGateLazarusMedusaNorth_KoreaOpenClawRATShinyHuntersSolarWinds_Serv-USteaeliteUNC2814credential_theftcryptostealerdata_breachdouble_extortionfirewall_compromisehardcoded_credentialsnpm_compromiseransomwareremote_code_executionsocial_engineeringsupply_chain_attack
What happened
A broad set of active and emerging threats was reported across multiple sectors. A new commodity RAT called Steaelite bundles credential and cryptocurrency stealers, live surveillance, and ransomware to facilitate double-extortion campaigns. Nation-state and state-linked activity includes suspected North Korean backdoors targeting US healthcare and education, and Lazarus Group adoption of Medusa ransomware. Multiple high-impact product vulnerabilities are being actively exploited or urgently warned about: a Five Eyes joint alert over Cisco Catalyst SD‑WAN bugs, four critical make-me-root flaws
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 1012e4b720f6078a67a5f3f8f9f780fa444a2e763b9da2a67e21dbc47ff45488
- Enrichment time
- 2026-03-04T22:48:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.