Microsoft Malware Targets Virtual Wallets
- A newly identified remote access Trojan, dubbed StilachiRAT, is targeting Google Chrome users with the goal of stealing sensitive data, particularly from cryptocurrency wallets.
- StilachiRAT employs sophisticated techniques to evade security systems and maintain persistence on infected devices.
- Once installed, the malware extracts passwords stored in Chrome, including access to extensions for approximately 20 wallets, such as Metamask, Trust Wallet, Coinbase, and Phantom.
New StilachiRAT Malware Targets Cryptocurrency Wallets
Table of Contents
A newly identified remote access Trojan, dubbed StilachiRAT, is targeting Google Chrome users with the goal of stealing sensitive data, particularly from cryptocurrency wallets. The malware was first detected in November 2024.
Threat Overview
StilachiRAT employs sophisticated techniques to evade security systems and maintain persistence on infected devices. It spreads through trojanized software, malicious emails, and fraudulent websites.
Once installed, the malware extracts passwords stored in Chrome, including access to extensions for approximately 20 wallets, such as Metamask, Trust Wallet, Coinbase, and Phantom. It also captures private keys and temporary codes copied by users.
The malware uses the Windows Services Control Manager (SCM) and surveillance threads to reactivate after removal attempts. it monitors remote desktop protocol (RDP) sessions to perhaps impersonate users and spread across networks. To avoid detection, StilachiRAT encrypts IP addresses in binary format, uses ports 53, 443, or 16000, deletes system records, checks for analysis tools, and obfuscates API calls.
Microsoft’s Response
Microsoft has released indicators of compromise (iocs) and recommends several security measures,including updating security solutions like Microsoft Defender,avoiding downloads from unverified sources,implementing two-factor authentication (2FA),and monitoring RDP connections and unusual activity on critical ports.
Although its distribution is limited, StilachiRAT represents a high risk due to its ability to extract data without leaving traces.
Microsoft is continuing to investigate the malware’s origin and will update defense measures as the analysis progresses.
Distribution and Objectives
The malware spreads through trojanized software, malicious emails, and fraudulent websites. While not yet attributed to a specific group, its primary target appears to be cryptocurrency users on Windows 10 and 11.
Mitigation Measures
Microsoft recommends the following actions to mitigate the risk of StilachiRAT infection:
- Update security solutions such as Microsoft Defender.
- Avoid downloads from unverified sources.
- Implement two-factor authentication (2FA).
- Monitor RDP connections and unusual activity on critical ports.
StilachiRAT Malware: Your Cryptocurrency Wallet’s Newest Threat
What is StilachiRAT?
StilachiRAT is a newly identified Remote Access Trojan (RAT) that poses a important threat to cryptocurrency users. First detected in November 2024, this malware specifically targets Google Chrome users with teh aim of stealing sensitive data from their cryptocurrency wallets.
How Does StilachiRAT Work?
StilachiRAT employs several sophisticated techniques to compromise systems and steal data. Here’s a breakdown of its operations:
Infection Vectors: The malware spreads through trojanized software, malicious emails, and fraudulent websites, tricking users into downloading and installing it.
Data Extraction: Once installed, StilachiRAT extracts sensitive data from Google Chrome, including saved passwords and access credentials for approximately 20 popular cryptocurrency wallets, such as Metamask, Trust Wallet, Coinbase, and Phantom. It also captures private keys and temporary codes copied by users.
Persistence: The malware uses the Windows Services Control Manager (SCM) and surveillance threads to ensure it reactivates even after removal attempts, maintaining its presence on the infected device.
Evasion Techniques: StilachiRAT uses various methods to avoid detection, including:
Encrypting IP addresses in binary format.
Utilizing ports 53, 443, or 16000.
Deleting system records.
Checking for analysis tools to evade security measures.
Obfuscating API calls to make its activity less obvious.
Network Propagation: StilachiRAT monitors Remote Desktop Protocol (RDP) sessions, potentially allowing attackers to impersonate users and spread the malware across networks.
What are the Targets of StilachiRAT?
The primary targets of StilachiRAT are cryptocurrency users on Windows 10 and 11. These users risk having their wallet credentials and other sensitive information stolen, leading to potential financial losses.
How Can I Protect Myself from StilachiRAT?
Microsoft has published indicators of compromise (IoCs) related to StilachiRAT and recommends several security measures to mitigate the risk of infection. Here’s what you can do:
Update Security Solutions: Ensure that your security solutions, such as Microsoft Defender, are updated to the latest versions.
Avoid Unverified Sources: be cautious about downloading software or clicking links from unverified sources,including suspicious emails or websites.
Implement Two-Factor Authentication (2FA): Enable 2FA on all your cryptocurrency accounts and other critical accounts to add an extra layer of security.
Monitor RDP Connections and unusual Activity: Regularly monitor your RDP connections and keep an eye out for unusual activity on critical ports to detect any signs of compromise.
Key Mitigation Measures: A Summary
The table below summarizes the key actions to take to protect yourself from stilachirat:
| Action | Description |
| :—————————————- | :—————————————————————————————————————————————- |
| Update Security Solutions | Keep security software like Microsoft Defender up-to-date to detect and block StilachiRAT. |
| Avoid Downloads from Unverified Sources | Only download software from trusted sources to prevent malware infections. |
| Implement Two-Factor Authentication (2FA) | Enable 2FA on all relevant accounts to add an extra layer of security, even if passwords are stolen. |
| monitor RDP Connections and Unusual Activity | Regularly check RDP connections and network activity to detect any suspicious behavior that could indicate a StilachiRAT infection. |
