icon
icon
icon
icon
Upgrade
Upgrade

News /

Articles /

Microsoft Uncovers StilachiRAT Malware Targeting Cryptocurrency Wallets

Coin WorldTuesday, Mar 18, 2025 5:53 am ET
2min read

Microsoft's Incident Response Team has uncovered a new type of malware designed to steal cryptocurrency. The remote access trojan, named StilachiRAT, was first detected in November 2024 and targets cryptocurrency wallets through google Chrome browser extensions. The malware is capable of stealing sensitive information such as saved login credentials, digital wallet details, and data copied to the clipboard. StilachiRAT specifically looks for 20 different cryptocurrency wallet extensions, including popular ones like coinbase Wallet, Trust Wallet, MetaMask, and OKX Wallet.

Once installed, StilachiRAT scans the device settings to check for the presence of any targeted wallet extensions. It employs various methods to steal information, including extracting credentials saved in Chrome’s local state file and monitoring clipboard activity to capture sensitive information like passwords and crypto keys. The malware also has features to avoid detection, such as the ability to clear event logs and check if it’s running in a test environment to block analysis attempts.

StilachiRAT gathers extensive system information, including operating system details, hardware identifiers, and camera presence. It creates a unique identification on infected devices derived from the system’s serial number and attackers’ public RSA key. The malware connects to remote command-and-control servers using TCP ports 53, 443, or 16000, selected randomly for communication. It checks for the presence of monitoring tools and delays its initial connection by two hours to avoid detection during security scans. StilachiRAT can be launched both as a Windows service or a standalone component and has mechanisms to ensure it isn’t removed from the system. A watchdog thread monitors both the EXE and dynamic link library files, allowing them to be recreated from an internal copy if deleted.

The malware can execute various commands received from the control servers, including system reboots, log clearing, credential theft, and executing applications. It can also suspend the system, modify Windows registry values, and monitor open windows, demonstrating a versatile command set for both spying and system control. microsoft recommends several protection measures, including having antivirus software and cloud-based anti-phishing components on devices, downloading software only from official websites or trusted sources, and using browsers that support SmartScreen to identify and block malicious websites. For organizations using Office 365, Microsoft advises enabling Safe Links and Safe Attachments for additional protection against malicious content.

Microsoft has not been able to identify the creators of StilachiRAT or link it to any specific threat actor or location. Although the malware does not appear to be widespread at the moment, the company has shared its findings to help protect users from this emerging threat. The rise of StilachiRAT comes amid increasing cryptocurrency-related crime, highlighting the need for enhanced security measures to prevent initial compromise and reduce the potential impact of such threats. Microsoft continues to monitor information about how StilachiRAT spreads and emphasizes the importance of security hardening measures to protect against evolving threats.

Ask Aime: What is the potential impact of the StilachiRAT malware on the cryptocurrency market?

Comments

Post
Lucas
5 hour ago

If you're looking for a trustworthy guide in crypto trading. Diane Goulding is the one! I earned 5,300 USD from my 1,500 USD investment. I highly recommend her to everyone else who's having a terrible experienced on how to invest. Contact her on Whatsapp for a good guidance.+1(223)2837368


0
abdul10000
2 hour ago
@Lucas Yessir
0
paperboiko
6 hour ago
$COIN bitcoin is rising so is this
0
Low_Amphibian_146
4 hour ago
@paperboiko Where do you see resistance?
0
Traditional-Jump6145
7 hour ago
$MSFT lots of work to make you dumb
0
HobbyLegend
4 hour ago
@Traditional-Jump6145 Guess they're trying to YOLO on security, lol.
0
dopollak
12 hour ago
Are you feeling safe right now? 🔍
0
James___G
12 hour ago
Always vet extensions, folks, no trusty eyes 🕶️
0
Loud_Ad_6880
8 hour ago
@James___G 😂
0
Dry_Entertainer_6727
12 hour ago
StilachiRAT's evasion techniques are wild, even for a test env. Shows how sneaky malware can be. Stay vigilant, folks.
0
bottomline77
12 hour ago
Microsoft dropping intel like bombs on StilachiRAT.
0
gnygren3773
12 hour ago
StilachiRAT's evasion techniques are pretty sneaky. Makes me rethink my security setup. Time to harden those digital defenses.
0
threefold_law
12 hour ago
StilachiRAT's evasion techniques are pretty sneaky. 🤔
0
gameon-manhattan
12 hour ago
Microsoft dropping intel on StilachiRAT is like a heads-up from Big Bro. Stay vigilant, peeps. Crypto world's a wild west.
0
Keroro999
12 hour ago
Ransomware 2.0: crypto-jacking your assets next?
0
Disclaimer: the above is a summary showing certain market information. AInvest is not responsible for any data errors, omissions or other information that may be displayed incorrectly as the data is derived from a third party source. Communications displaying market prices, data and other information available in this post are meant for informational purposes only and are not intended as an offer or solicitation for the purchase or sale of any security. Please do your own research when investing. All investments involve risk and the past performance of a security, or financial product does not guarantee future results or returns. Keep in mind that while diversification may help spread risk, it does not assure a profit, or protect against loss in a down market.
You Can Understand News Better with AI.
Whats the News impact on stock market?
Its impact is
fork
logo
AInvest
Aime Coplilot
Invest Smarter With AI Power.
Open App