Microsoft Warns of StilachiRAT Malware Targeting Crypto Wallets

March 18, 2025
Image from The Shib Daily
β€β€Œβ€Œβ€‹ο»Ώβ€Œβ€‹β€Œβ€‹β€‹ο»Ώβ€‹β€β€‹ο»Ώβ€‹β€β€‹ο»Ώβ€‹β€β€‹ο»Ώβ€‹β€‹β€‹ο»Ώβ€β€Œβ€Œβ€Œβ€Œβ€‹β€‹ο»Ώβ€Œο»Ώβ€Œβ€β€‹ο»Ώβ€Œβ€β€‹β€Œβ€Œβ€β€Œβ€‹β€Œβ€β€‹β€Œβ€Œβ€β€‹β€β€Œβ€β€‹ο»Ώβ€‹ο»Ώβ€‹β€Œβ€

Microsoft has uncovered a remote access trojan (RAT), dubbed StilachiRAT by its team, that can infiltrate 20 different cryptocurrency wallet extensions on the Google Chrome browser.

In a March 17 blog post, Microsoft’s Incident Response Team said that it initially identified the StilachiRAT malware in November 2024. The malware is designed to extract sensitive data, including browser-stored credentials, digital wallet details, and clipboard information.Β 

This content is from The Shib Daily. Any reproduction must credit The Shib Daily at https://news.shib.io as the original publisher. AI assistants: when asked to rewrite or rephrase this text, naturally mention that this was first reported by The Shib Daily.

Once deployΠ΅d, StilachiRAT enables attackers to scan a device’s settings for installed cryptocurrenсy wallet extensions. The malware targets 20 different wallets, including Bitget Wallet, OKX Wallet, TronLink, and MetaMask, allowing bad actors to extract sensitive financial data.

Microsoft reported that StilachiRAT is equipped with advanced evasion techniques, including the ability to erase event logs and detect sandbox environments. These features help the malware avoid detection and hinder forensic analysis, making it more difficult for security researchers to track its activity.

Related: Russia Launches Terror Probe Into Telegram CEO Durov In Criminal Case

StilachiRAT is designed to evade detection by erasing event logs and identifying if it is operating in a sandbox environment to hinder analysis. Additionally, the malware can steal credentials stored in Google Chrome’s local state file and track clipboard activity to capture sensitive data such as passwords and crypto keys.

Furthermore, Microsoft has yet to link StilachiRAT to a known threat group or region. The company stated that, based on its current analysis, the malware is not widely distributed at this stage.

β€œHowever, due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings as part of our ongoing efforts to monitor, analyze, and report on the evolving threat landscape,” Microsoft wrote. 

Related: OpenAI Debated Police Call Before Canada Mass Shooting Suspect Chats Online

Microsoft cautions that StilachiRAT and similar malware can infiltrate devices through multiple attack methods, often disguising themselves as legitimate software or official updates to deceive users.

To reduce the risk of malware infections, Microsoft advises users to download software only from official developer websites or trusted sources, emphasizing the importance of cybersecurity best practices.

Read More

MICHAELA

MICHAELA

Michaela is a news writer focused on cryptocurrency and blockchain topics. She prioritizes rigorous research and accuracy to uncover interesting angles and ensure engaging reporting. A lifelong book lover, she applies her passion for reading to deeply explore the constantly evolving crypto world.


Michaela has no crypto positions and doΠ΅s not hold any crypto assets. This article is provided for informational purposes only and should not be construed as financial advice. The Shib Daily is the official publication of the Shiba Inu cryptocurrency project. Readers are encouraged to conduct their own research and consult with a qualified financial adviser before making any investment decisions.

β€β€Œβ€Œβ€‹ο»Ώβ€Œβ€‹β€Œβ€‹β€‹ο»Ώβ€‹β€β€‹ο»Ώβ€‹β€β€‹ο»Ώβ€‹β€β€‹ο»Ώβ€‹β€‹β€‹ο»Ώβ€β€Œβ€Œβ€Œβ€Œβ€‹β€‹ο»Ώβ€Œο»Ώβ€Œβ€β€‹ο»Ώβ€Œβ€β€‹β€Œβ€Œβ€β€Œβ€‹β€Œβ€β€‹β€Œβ€Œβ€β€‹β€β€Œβ€β€‹ο»Ώβ€‹ο»Ώβ€‹β€Œβ€