Saturday, 22 February 2025
27.8 C
Singapore
33.4 C
Thailand
21.1 C
Indonesia
26.4 C
Philippines

New malware SteelFox targets Windows users through fake software activators

Beware of SteelFox malware, targeting Windows users worldwide with fake activators for AutoCAD, JetBrains, and Foxit, causing data theft and cryptojacking.

A new cyber threat is making waves across the world, targeting Windows users with a malicious strategy thatโ€™s becoming alarmingly common. Known as โ€œSteelFox,โ€ this malware package uses fake software activators to infect Windows systems with cryptocurrency mining and data-stealing tools, affecting tens of thousands of computers worldwide.

Experts from Kaspersky report that since February 2023, cybercriminals have been actively distributing SteelFox via torrent sites and online forums. The malware is disguised as legitimate โ€œcracksโ€ or โ€œactivatorsโ€ for popular software like AutoCAD, JetBrains, and Foxit PDF Editor. These fake activators, which promise users access to full versions of costly software, have instead turned into a direct route for hackers to gain access to usersโ€™ systems.

How the SteelFox malware operates

When unsuspecting users download and install these fake activators, a risky driver named WinRingO.sys is also installed, which reopens two old vulnerabilities โ€” CVE-2021-41285 and CVE-2020-14979 โ€” previously patched but now re-exploited by hackers. By installing these vulnerabilities, attackers gain full access to your computer, allowing them to infiltrate the system and take advantage of your resources.

One of the primary tools hackers use is a crypto miner called XMRig, which hijacks your systemโ€™s processing power, electricity, and internet bandwidth to mine Monero and other cryptocurrencies, a process known as crypto jacking. This makes your computer run slower, overheat, and use excessive power, resulting in a significantly compromised system and increased utility bills.

The malware also contains an โ€œinfo stealerโ€ program that harvests sensitive information from over 13 web browsers, including details like credit card numbers, browsing history, and login credentials. This stolen data can be used for further attacks or sold on the dark web, potentially leading to identity theft and financial loss. Additionally, hackers establish a Remote Desktop Protocol (RDP) connection to maintain control over the infected device, giving them unrestricted access whenever they choose.

A growing global issue

Kasperskyโ€™s report reveals that SteelFox is not limited to a specific region; attacks have been detected worldwide. Countries with high infection rates include Mexico, Brazil, Russia, China, the United Arab Emirates, Algeria, Egypt, Vietnam, Sri Lanka, and India. The number of reported infections continues to grow, and Kaspersky has blocked over 11,000 attempted attacks so far, though the true count may be much higher.

The malware is complicated to detect because it appears to follow the typical steps of software installation, creating an illusion of legitimacy until the files are unpacked and the harmful code is unleashed. Kaspersky warns that some online posts have shared full instructions for launching the software illegally, encouraging users to bypass paid licenses with these infected cracks, inadvertently inviting SteelFox into their systems.

How to stay safe from SteelFox

With threats like SteelFox on the rise, cybersecurity experts strongly advise downloading software only from official and verified sources. Relying on torrents and unofficial sites is one of the easiest ways to compromise your device inadvertently. Having reliable, up-to-date antivirus software is also critical. Products from reputable providers, such as Bitdefender, can help detect and block threats like SteelFox before they gain a foothold in your system.

Taking preventive measures is essential to safeguard your data and computing resources. Avoid pirated software, use strong and unique passwords, and ensure your operating system and all applications are up to date with the latest security patches. While SteelFox is a serious threat, these steps can significantly reduce your chances of becoming a victim.

Hot this week

Baidu embraces DeepSeek AI to enhance search experience

Baidu integrates DeepSeek AI into its search engine, following Tencentโ€™s move with Weixin. Chinaโ€™s AI race heats up as DeepSeek gains popularity.

SAP launches Business Data Cloud with Databricks to enhance AI-powered decision-making

SAP launches Business Data Cloud with Databricks, unifying enterprise data and enhancing AI-driven decision-making with Joule agents.

Apple may introduce reverse wireless charging on iPhone 17 Pro

Apple may introduce reverse wireless charging in the iPhone 17 Pro, allowing users to power AirPods and Apple Watch without extra cables.

‘TeslaTakeover’ protests continue to grow, albeit small in number

Protests continue to grow, targeting Tesla showrooms over Elon Muskโ€™s political actions, with more expected during the Presidentโ€™s Day holiday.

Google Play Books introduces direct purchases on iOS

Google Play Books now allows direct purchases on iOS, bypassing Appleโ€™s fees. A new โ€œGet bookโ€ button links users to Google Play for payments.

Nvidia acknowledges RTX 5090 and 5070 Ti manufacturing defect

Nvidia confirms a rare manufacturing defect in the RTX 5090 and 5070 Ti, affecting less than 0.5% of GPUs. Affected users can request a replacement.

DJIโ€™s RS 4 Mini stabiliser now features advanced subject tracking

DJIโ€™s RS 4 Mini stabiliser introduces subject tracking, improved battery life, and better handling, making it an excellent tool for content creators.

American Airlines introduces AirTag location sharing for lost luggage

American Airlines now supports Appleโ€™s AirTag location sharing, making it easier for passengers to track and recover lost luggage.

Google may launch YouTube Premium Lite in more countries

Google may launch YouTube Premium Lite in the US, Australia, Germany, and Thailand, offering a cheaper plan with fewer ads. Pricing is yet to be confirmed.

Related Articles