BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New RATs Target Windows, Game Utilities for Access

Rising RAT threats: Steaelite, gaming Trojan, and DesckVB KazakRAT variants emerge.

  • Attackers are distributing a new Remote Access Trojan (RAT) disguised as gaming software through browsers and chat apps.
  • The malware uses stealthy techniques, modifies Microsoft Defender, and connects to an external server for command-and-control.
  • A powerful new “all-in-one” RAT called Steaelite is being advertised on criminal forums, combining data theft with ransomware deployment from a single panel.
  • Two additional new RAT families, DesckVB RAT and KazakRAT, have also been discovered targeting specific entities.

In late February 2026, researchers uncovered a campaign where cybercriminals distribute trojanized gaming utilities via online platforms to deploy a remote access trojan. The Microsoft Threat Intelligence team explained the attack uses a malicious Java downloader and living-off-the-land binaries for stealth. This multi-purpose malware acts as a loader, runner, and RAT to exfiltrate data and deploy other payloads.

- Advertisement -

The threat also establishes persistence and configures Microsoft Defender exclusions to avoid detection. Consequently, defenders are advised to audit these exclusions and scheduled tasks immediately. Meanwhile, a separate, far more comprehensive threat has emerged on the cybercrime market.

BlackFog disclosed a new Windows RAT family first advertised in November 2025 called Steaelite, marketed as a “best Windows RAT” with fully undetectable capabilities. Security researcher Wendy McCague said it “enables complete double extortion from one tool” by combining ransomware with data theft. The tool can disable antivirus, remove competing malware, and offers extensive features like live streaming and credential theft.

In recent weeks, two other new RAT families have also been discovered. One is the open-source DesckVB RAT available on GitHub, providing remote control capabilities. The other, KazakRAT, is suspected to be the work of a state-affiliated group and has been detailed in a report by Ctrl Alt Intel. This campaign has reportedly been targeting Kazakh and Afghan entities since at least August 2022.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SNDK’s Wild Ride: Next Stop $2K or $1K?

SanDisk stock (NASDAQ: SNDK) hit a yearly high of $2,354 before plunging to $985,...

UK regulator HTX in settlement talks over illegal crypto ads

Britain's Financial Conduct Authority and HTX are in talks to settle the regulator's claim...

Tesla needs marketing push for robotaxis, Optimus: Fund manager

Future Fund Managing Partner Gary Black argues Tesla needs a long-term marketing strategy, not...

SEC Clears Franklin Templeton to Invest in Onchain Money Fund

The SEC issued a no-action letter allowing Franklin Templeton funds to invest in its...

SharePoint CVE-2026-55040 exploited after PoC release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after...

Must Read

What Are Anonymous Debit Cards And How Do They Work?

You've heard about anonymous debit cards, but what are they really? Anonymous Debit Cards are cards that let you make purchases without revealing your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading