Microsoft has recently alerted users about a new remote access trojan (RAT) named StilachiRAT, which poses a significant threat to cryptocurrency holders. This malware is designed to stealthily infiltrate systems, extract sensitive information, and evade detection, particularly targeting popular crypto wallet extensions in the Google Chrome browser.
Key Takeaways
-
StilachiRAT is a sophisticated RAT that targets cryptocurrency wallets.
-
It can extract credentials from browsers and monitor clipboard activity.
-
The malware employs advanced techniques to avoid detection and maintain persistence.
-
Microsoft has not yet attributed the malware to any specific threat actor.
Overview of StilachiRAT
Discovered by Microsoft’s Incident Response Team in November 2024, StilachiRAT is engineered to gather extensive system information and steal sensitive data. It specifically targets 20 cryptocurrency wallet extensions, including popular options like Coinbase Wallet, MetaMask, and Trust Wallet. The malware operates by scanning for these extensions and extracting user credentials stored in the browser.
StilachiRAT threatens 20 different wallet extensions: Microsoft
How StilachiRAT Operates
StilachiRAT utilizes a DLL module named WWStartupCtrl64.dll to execute its malicious activities. Here are some of its key functionalities:
-
Data Extraction: It can siphon off credentials saved in the Google Chrome local state file and monitor clipboard activity for sensitive information such as passwords and cryptocurrency keys.
-
System Profiling: The malware collects detailed system information, including hardware identifiers, active Remote Desktop Protocol (RDP) sessions, and running applications.
-
Command Execution: StilachiRAT establishes a connection with a command-and-control (C2) server, allowing attackers to execute commands remotely, such as rebooting the system, clearing logs, and manipulating applications.
Evasion Techniques
One of the most concerning aspects of StilachiRAT is its ability to evade detection. The malware employs several anti-forensic tactics, including:
-
Clearing Event Logs: This helps it avoid detection by security software.
-
Sandbox Detection: It checks for signs of being analyzed in a sandbox environment, which can prevent it from activating fully in such settings.
-
Dynamic Obfuscation: The malware uses dynamic checksums for its API calls, making it harder for analysts to dissect its operations.
Current Threat Landscape
While StilachiRAT has not yet achieved widespread distribution, its emergence comes at a time when cyberattacks targeting cryptocurrency users are on the rise. According to recent reports, losses attributed to crypto-related scams and hacks reached approximately $1.53 billion in February 2025 alone, with a significant portion stemming from a single incident involving the Bybit exchange.
Recommendations for Users
To protect against threats like StilachiRAT, Microsoft advises users to:
-
Download software only from official sources.
-
Use web browsers that support security features like SmartScreen.
-
Enable Safe Links and Safe Attachments in Office 365.
-
Implement robust antivirus and anti-malware solutions.
As the landscape of cybercrime continues to evolve, it is crucial for cryptocurrency users to remain vigilant and enhance their cybersecurity practices to safeguard their digital assets.
Sources
-
A Stealthy RAT Targeting Credentials and Crypto Wallets, The Hacker News.
-
Microsoft: New RAT malware used for crypto theft, reconnaissance, BleepingComputer.
-
"Sophisticated" StilachiRAT Exploits Chrome for Crypto Wallets and Credentials, Hackread.
-
Microsoft warns of new remote access trojan targeting crypto wallets, IDF Spokesperson Blog.
-
Microsoft Warns of New Trojan Stealing Crypto in Wallet Extensions, cryptonews.com.
This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.