Steaelite Windows RAT with FUD and multi-function capabilities
Malware Activity
Summary
Hide ▲
Show ▼
The Steaelite Windows RAT is being marketed as a fully undetectable tool for Windows 10 and 11, giving operators browser-based control over infected machines and enabling credential theft, surveillance, and ransomware deployment. It was first advertised on criminal forums in November 2025, making the malware family newly visible to defenders and buyers. Its bundled capabilities increase the risk of double extortion from a single operator dashboard.
Related Happenings
LabubaRAT Rust RAT masquerading as NVIDIA software on Windows
Malware Activity
H score24
First: 14.07.2026 19:52
Last: 14.07.2026 19:52
Sources 1
About this happening:
A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...
LabubaRAT Rust RAT masquerading as NVIDIA software on Windows
Malware ActivityAbout this happening: A newly documented Rust-based RAT, LabubaRAT, now gives operators Windows host control with file movement, screenshot capture, and traffic proxying. The malware masq...
GigaWiper reuses multiple malware lineages in a unified destructive backdoor
Technical Analysis
H score22
First: 10.07.2026 18:30
Last: 10.07.2026 18:30
Sources 1
About this happening:
Microsoft's July 9 analysis of GigaWiper shows a modular backdoor that merges espionage, C2, and destructive wiping into one implant, widening the damage a sin...
GigaWiper reuses multiple malware lineages in a unified destructive backdoor
Technical AnalysisAbout this happening: Microsoft's July 9 analysis of GigaWiper shows a modular backdoor that merges espionage, C2, and destructive wiping into one implant, widening the damage a sin...
GigaWiper modular backdoor with wiping and espionage capabilities
Malware Activity
H score22
First: 10.07.2026 18:30
Last: 10.07.2026 18:30
Sources 1
About this happening:
The newly analyzed GigaWiper backdoor combines espionage and destructive wiping functions, giving operators a single implant that can control, sabotage, and erase infe...
GigaWiper modular backdoor with wiping and espionage capabilities
Malware ActivityAbout this happening: The newly analyzed GigaWiper backdoor combines espionage and destructive wiping functions, giving operators a single implant that can control, sabotage, and erase infe...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Gentlemen ransomware EDR-killer tooling
Malware Activity
H score35
First: 19.06.2026 01:31
Last: 19.06.2026 01:31
Sources 1
About this happening:
Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says t...
Gentlemen ransomware EDR-killer tooling
Malware ActivityAbout this happening: Gentlemen ransomware-as-a-service (RaaS) is actively maintaining a suite of EDR killers led by GentleKiller to disable endpoint defenses before encryption. ESET says t...
Timeline
-
27.02.2026 12:06 2 articles · 4mo ago
Steaelite Windows RAT disclosed with FUD marketing and browser-based control
Initial DisclosureBlackFog disclosed Steaelite, a new Windows RAT family first advertised on criminal forums in November 2025 as a "best Windows RAT" with "fully undetectable" (FUD) capabilities. Steaelite targets Windows 10 and 11 through a browser-based web panel and combines remote code execution, live surveillance, file exfiltration, password theft, persistence, Microsoft Defender disabling, and ransomware deployment from one dashboard.
Show sources
- Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms — thehackernews.com — 27.02.2026 12:06
- Trojanized Gaming Tools Spread Java-Based RAT via Browser and Chat Platforms — thehackernews.com — 27.02.2026 12:06