Episode

A new breed of RAT. [Research Saturday]

Podcast
CyberWire Daily
Published
Apr 18, 2026
Duration seconds
1312
Processing state
processed
Canonical source
https://thecyberwire.com/podcasts/research-saturday/421/notes
Audio
https://pdst.fm/e/pdrl.fm/85df76/traffic.megaphone.fm/CYBW4653324224.mp3?updated=1776448577
JSON
/v1/public/podcasts/cyberwire-daily-454880/episodes/a-new-breed-of-rat-research-saturday
Markdown
/podcast/cyberwire-daily-454880/a-new-breed-of-rat-research-saturday.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/a-new-breed-of-rat-research-saturday/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberwire-daily-454880/a-new-breed-of-rat-research-saturday.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Today we are joined by Dr. Darren Williams, Founder and CEO of BlackFog, to discuss his team's work on "Steaelite RAT Enables Double Extortion Attacks from a Single Panel." A new remote access trojan, Steaelite, is being marketed on underground forums as an all-in-one platform that combines remote access, credential theft, surveillance, and ransomware deployment through a single browser-based dashboard. Unlike traditional cybercrime toolchains, it merges data exfiltration and ransomware capabilities into one interface, with automated credential harvesting beginning as soon as a victim is infected. The tool signals a growing shift toward streamlined “double extortion” attacks, where data theft and encryption happen within the same system—raising the stakes for defenders to stop threats before data is exfiltrated. The research and executive brief can be found here: Steaelite RAT Enables Double Extortion Attacks from a Single Panel Learn more about your ad choices. Visit megaphone.fm/adchoices