Breaking
April 16, 2025

Microsoft Security Team Reveals Details of StilachiRAT Cryptocurrency Theft Malware Maisie Morrison | usagoldmines.com

TLDR

  • Microsoft identified a new remote access trojan (StilachiRAT) that targets 20 cryptocurrency wallet extensions in Google Chrome
  • The malware can steal browser credentials, wallet information, and clipboard data while using evasion techniques to avoid detection
  • StilachiRAT creates a unique device ID, monitors RDP sessions, and establishes communication with command-and-control servers
  • The malware can execute 10 different commands including system shutdown, log clearing, and application launching
  • Despite not being widespread currently, Microsoft released the information to help users protect themselves from this emerging threat

Microsoft has discovered a new type of malware specifically designed to steal cryptocurrency. The tech company’s Incident Response Team first found the remote access trojan (RAT) in November 2024.

The malware, named StilachiRAT, targets cryptocurrency wallets through Google Chrome browser extensions. Microsoft shared their findings in a March 17 blog post.

StilachiRAT can steal sensitive information stored in browsers. This includes saved login credentials, digital wallet details, and data copied to the clipboard.

The malware works by looking for 20 different cryptocurrency wallet extensions. These include popular wallets like Coinbase Wallet, Trust Wallet, MetaMask, and OKX Wallet.

Once installed, StilachiRAT scans your device settings. It checks if any of the targeted wallet extensions are present on your system.

The trojan uses several methods to steal information. It can extract credentials saved in Chrome’s local state file.

It also monitors clipboard activity. This allows it to capture sensitive information like passwords and crypto keys as users copy them.

Microsoft explained that StilachiRAT has features to avoid detection. These include the ability to clear event logs.

The malware can also check if it’s running in a test environment. This helps it block attempts to analyze how it works.

Currently, Microsoft cannot identify who created the malware. They haven’t linked it to any specific threat actor or location.

The company stated that StilachiRAT doesn’t appear to be widespread right now. However, they decided to share their findings to help protect users.

“Due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings,” Microsoft wrote. This is part of their effort to monitor and report on evolving threats.

Inside StilachiRAT: Theft Tactics Revealed

StilachiRAT gathers extensive system information. This includes operating system details, hardware identifiers, and camera presence.

The malware creates a unique identification on infected devices. This ID is derived from the system’s serial number and attackers’ public RSA key.

StilachiRAT connects to remote command-and-control servers. It uses TCP ports 53, 443, or 16000, selected randomly for communication.

The malware checks for the presence of monitoring tools. It won’t proceed if it detects certain security software running.

StilachiRAT delays its initial connection by two hours. This is likely an attempt to avoid detection during security scans.

The malware can be launched both as a Windows service or a standalone component. It has mechanisms to ensure it isn’t removed from the system.

A watchdog thread monitors both the EXE and dynamic link library files. If these files are deleted, they can be recreated from an internal copy.

StilachiRAT can execute various commands received from the control servers. These include system reboots, log clearing, credential theft, and executing applications.

The malware can also suspend the system, modify Windows registry values, and monitor open windows. This shows a versatile command set for both spying and system control.

Microsoft recommends several protection measures. Users should have antivirus software and cloud-based anti-phishing components on their devices.

The company advises downloading software only from official websites or trusted sources. This helps avoid RATs that masquerade as legitimate software.

Microsoft encourages users to use browsers that support SmartScreen. This feature can identify and block malicious websites, including phishing sites.

For organizations using Office 365, Microsoft recommends enabling Safe Links and Safe Attachments. These features provide additional protection against malicious content.

The rise of StilachiRAT comes amid increasing cryptocurrency-related crime. According to blockchain security firm CertiK, losses to crypto scams and hacks totaled nearly $1.53 billion in February alone.

Blockchain analytics firm Chainalysis reported $51 billion in illicit transaction volume in their 2025 Crypto Crime Report. They noted that crypto crime has entered a more professional era.

The report highlighted AI-driven scams, stablecoin laundering, and efficient cyber criminal organizations. These tactics show how crypto theft methods continue to evolve.

Microsoft continues to monitor information about how StilachiRAT spreads. They note that malware like this can be installed through multiple vectors.

The company emphasizes that security hardening measures are critical. These help prevent initial compromise and reduce the potential impact of such threats.

The post Microsoft Security Team Reveals Details of StilachiRAT Cryptocurrency Theft Malware appeared first on Blockonomi.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Strategy Acquires 3,459 Bitcoin for $285.8 Million, Total Holdings Reach 531,644 BTC Maisie Morrison...

Michael Saylor Hints at New Bitcoin Acquisitions for MicroStrategy Maisie Morrison | usagoldmines.co...

Metaplanet Acquires $26.3 Million in Bitcoin, Plans 470% Holdings Increase by Year-End Maisie Morris...

Meta Whistleblower to Testify About Company’s Secret AI Cooperation with China Maisie Morrison | usa...

Strategy Reports $5.91 Billion Unrealized Bitcoin Loss in Q1 2025 Maisie Morrison | usagoldmines.com

Strategy Reports $5.91 Billion in Unrealized Bitcoin Losses for Q1 2025 Maisie Morrison | usagoldmin...

BlackRock CEO Larry Fink Predicts Possible 20% Further Market Decline Maisie Morrison | usagoldmines...

Gemini Exchange Leases Miami Office Space as SEC Case Paused Maisie Morrison | usagoldmines.com

Elon Musk’s X Faces Billion-Dollar EU Fine Over Content Moderation Failures Maisie Morrison | usagol...

Trump Media Stock Falls After SEC Filing for Potential Share Sale Maisie Morrison | usagoldmines.com

OnlyFans Founder and HBAR Foundation Submit Late Bid for TikTok Maisie Morrison | usagoldmines.com

Trump Brothers and Hut 8 Launch American Bitcoin Mining Venture with Plans to Go Public Maisie Morri...

Corporate Bitcoin Holdings Expected to Reach 25% of S&P 500 by 2030 Maisie Morrison | usagoldmin...

MARA Holdings Announces $2 Billion Stock Offering to Purchase Bitcoin Maisie Morrison | usagoldmines...

Metaplanet Issues ¥2 Billion in Zero-Interest Bonds to Fund Bitcoin Acquisitions Maisie Morrison | u...

France’s Bpifrance Allocates €25 Million for Blockchain Investment Maisie Morrison | usagoldmines.co...

The Blockchain Group Adds 580 Bitcoin to Treasury Holdings Maisie Morrison | usagoldmines.com

GameStop to Raise $1.4 Billion for Bitcoin Treasury Investment Maisie Morrison | usagoldmines.com

Crusoe Energy Sells Bitcoin Mining Operations to NYDIG, Focuses on AI Infrastructure Maisie Morrison...

GameStop Adds Bitcoin to Investment Policy Following Board Approval Maisie Morrison | usagoldmines.c...

Metaplanet Increases Bitcoin Holdings to 3,350 BTC, Valued at $291 Million Maisie Morrison | usagold...

Metaplanet Appoints Eric Trump to New Bitcoin Advisory Board Maisie Morrison | usagoldmines.com

Robinhood Receives ‘Buy’ Rating as Crypto Revenue Surges 700% in Q4 Maisie Morrison | usagoldmines.c...

Solana CEO Issues Apology for Advertisement Criticized as Discriminatory Maisie Morrison | usagoldmi...

Bakkt Stock Falls 27% Following Loss of Bank of America and Webull Partnerships Maisie Morrison | us...

Filmmaker Charged with Defrauding Netflix of $11 Million for Unfinished Series Maisie Morrison | usa...

Metaplanet Issues ¥2 Billion in Zero-Interest Bonds to Purchase Additional Bitcoin Maisie Morrison |...

Ark Invest Expands Crypto Holdings with $80M Bitcoin Purchase and $5.2M Coinbase Investment Oliver D...

Rumble Adds Bitcoin to Corporate Treasury with $17.1 Million Purchase Oliver Dale | usagoldmines.com

Metaplanet Acquires 162 Bitcoin for $13.5 Million, Issues New Bonds Oliver Dale | usagoldmines.com

Redacted to Launch RDAC Token on MocaList, Powered by Mocaverse and Coin List Oliver Dale | usagoldm...

Robinhood Settles FINRA Probes for $29.75 Million Over Compliance Issues Maisie Morrison | usagoldmi...

Blockstream Secures Multi-Billion Investment to Launch Bitcoin Lending Funds Oliver Dale | usagoldmi...

Metaplanet Boosts Bitcoin Holdings with $44 Million Purchase as Stock Surges Oliver Dale | usagoldmi...

Reddit Co-Founder Alexis Ohanian Joins Bid to Acquire TikTok & Move It to Blockchain Oliver Dale...

Metaplanet Increases Bitcoin Holdings to 2,391 BTC with New Purchase Maisie Morrison | usagoldmines....

Bitcoin Miner MARA Posts $214.4 Million Q4 Revenue, Beating Market Estimates Oliver Dale | usagoldmi...

AI Cloud Provider CoreWeave Plans $4 Billion IPO Filing as AI Cloud Computing Demand Surges Oliver D...

Nvidia (NVDA) Delivers Record Q4 Results Despite Recent AI Market Turbulence Oliver Dale | usagoldmi...

GameStop CEO Ryan Cohen Considers $4.6 Billion Bitcoin Purchase Recommendation Maisie Morrison | usa...

Strategy Adds 20,356 Bitcoin Worth $2 Billion to Holdings, Approaches 500,000 BTC Milestone Maisie M...

Market Maker Giant Wintermute Plans US Expansion as Regulatory Winds Shift Nicholas Say | usagoldmin...

Binance Co-Founders Refute Exchange Sale Rumors Maisie Morrison | usagoldmines.com

Bloomberg Launches Combined Bitcoin and Gold Investment Indices Maisie Morrison | usagoldmines.com

Metaplanet Secures MSCI Japan Listing with 1,762 Bitcoin Holdings Maisie Morrison | usagoldmines.com

KULR Technology Group Expands Bitcoin Treasury to 610 BTC Oliver Dale | usagoldmines.com

Riot Platforms Announces AI Computing Initiative and Board Appointments Maisie Morrison | usagoldmin...

Metaplanet Announces ¥4 Billion Bond Issue for Bitcoin Treasury Expansion Maisie Morrison | usagoldm...

LinksDAO Expands with New Token Launch & Historic Kansas City Golf Course Acquisition Oliver Dal...

Goldman Sachs Q4 Filing Shows $1.5B Bitcoin ETF Investment Maisie Morrison | usagoldmines.com

$1 Billion in Bitcoin: Tesla (TSLA) Reports $600 Million Bitcoin Gain Under New Accounting Rules Oli...

Bold Move: Elon Musk-Led Investor Group Offers $97.4B for OpenAI Acquisition Oliver Dale | usagoldmi...

Metaplanet Stock Rises 3,600% After Bitcoin Investment Strategy Maisie Morrison | usagoldmines.com

Ondo Finance Launches Specialized Blockchain for Real-World Asset Tokenization Maisie Morrison | usa...

From Micro to Macro: Strategy Rebrand Signals Software Company’s Transition to Bitcoin Focus Oliver ...

Singularity Finance Teams Up with Functionland to Boost Web3 Development Tool Oliver Dale | usagoldm...

Nuvve to Convert 30% of Excess Cash to Bitcoin Holdings Oliver Dale | usagoldmines.com

MicroStrategy Shareholders Approve 10.3 Billion Share Authorization for Bitcoin Strategy Oliver Dale...

TRON DAO Expands Wintermute Partnership to Boost Trading Liquidity Oliver Dale | usagoldmines.com

Video Platform Rumble Initiates Bitcoin Strategy with First Purchase Oliver Dale | usagoldmines.com

Komainu Secures $75M Bitcoin Investment from Blockstream Capital Partners Oliver Dale | usagoldmines...

MicroStrategy Reaches 450,000 Bitcoin Milestone After Latest Buy Oliver Dale | usagoldmines.com

Corporate Bitcoin Treasury Holdings Exceed 1 Million BTC in 2025 Oliver Dale | usagoldmines.com

Fidelity Report Details Bitcoin’s Transition from Speculation to Adoption Oliver Dale | usagoldmines...

MicroStrategy (MSTR) Trading Volume Matches Tech Giants as Corporate Bitcoin Holdings Grow Oliver Da...

Metaplanet Announces Multi-Billion Yen Bitcoin Investment Plan Oliver Dale | usagoldmines.com

XRP Price Up 300%: Ripple Reports Increased US Deal Flow Following Presidential Election Oliver Dale...

MARA Loans 16% of Its Bitcoin Reserves to Generate Additional Income Nicholas Say | usagoldmines.com

Metaplanet Acquires Another 620 Bitcoin: Total Holdings Reach 1,762 BTC Oliver Dale | usagoldmines.c...

Formula 1 Renews Crypto.com Partnership Through 2030 Oliver Dale | usagoldmines.com

Aptos Labs Announces CEO Transition: Mo Shaikh Steps Down, Avery Ching Takes Over Oliver Dale | usag...

Chainalysis Expands Security Operations with Hexagate Purchase Oliver Dale | usagoldmines.com

Coinbase Reports Decline in Government Information Requests for 2024 Oliver Dale | usagoldmines.com

Revolut Expands Security Measures for Cryptocurrency Customers Oliver Dale | usagoldmines.com

Metaplanet Stock Hits Record High Following Bitcoin Investment Plan Oliver Dale | usagoldmines.com

Less than 1% of Microsoft Shareholders Support Bitcoin Investment Plan Oliver Dale | usagoldmines.co...

MicroStrategy to Join Nasdaq 100 Index with $2.1B Expected ETF Investment Oliver Dale | usagoldmines...

Coinbase and Chainlink Partner for Tokenized Asset Solutions Oliver Dale | usagoldmines.com

Binance Partners with Circle to Integrate USDC Across Trading Platform Oliver Dale | usagoldmines.co...

Microsoft Shareholders Decline $800M Bitcoin Investment Strategy Oliver Dale | usagoldmines.com

OKX Ventures Commits $5 Million to TON Ventures, Boosting Telegram-Native Blockchain Development Oli...

Amazon Shareholders Propose 5% Bitcoin Treasury Investment Oliver Dale | usagoldmines.com

OpenAI Disputes New York Times Copyright Claims in Ongoing Legal Battle Oliver Dale | usagoldmines.c...

MicroStrategy Sees Over $18b in Gains as Bitcoin Hits $100k Mark Nicholas Say | usagoldmines.com

Semler Scientific Reports 78.7% BTC Yield After Latest Bitcoin Purchase Oliver Dale | usagoldmines.c...

Marathon Digital (MARA) Purchases Texas Wind Farm for Bitcoin Mining Operations Oliver Dale | usagol...

Delaware Court Rejects Tesla’s $56B Musk Compensation Package Oliver Dale | usagoldmines.com

Coinbase Expands Payment Options with New Apple Pay Feature Oliver Dale | usagoldmines.com

MicroStrategy Adds 15,400 Bitcoin to Corporate Treasury in December Purchase Oliver Dale | usagoldmi...

Saylor Presents Bitcoin Treasury Strategy to Microsoft Executives Oliver Dale | usagoldmines.com

Former Libra Head Details Political Pressure That Ended Meta’s Digital Currency Oliver Dale | usagol...

Metaplanet Launches Bitcoin Shareholder Reward Program Worth 30M Yen Oliver Dale | usagoldmines.com

MicroStrategy (MSTR) Expands Bitcoin Holdings with $4.6 Billion Purchase, Announces $1.75 Billion No...

MicroStrategy Acquires $4.6 Billion in Bitcoin as Stock Hits Record High Oliver Dale | usagoldmines....

Japanese Firm Reports 155% Bitcoin Yield in Q3 2024 Oliver Dale | usagoldmines.com

Nvidia (NVDA): AI Chip Dominance Could Drive $37B Revenue in Q4 Oliver Dale | usagoldmines.com

Nvidia (NVDA): AI Chip Dominance Could Drive $37B Revenue in Q4 Oliver Dale | usagoldmines.com

Tesla Reports $495 Million Profit on Bitcoin Investment Oliver Dale | usagoldmines.com

Tether (USDT) Enters Oil Trade with $45M Middle Eastern Crude Deal Oliver Dale | usagoldmines.com

Crypto Venture Capital Reaches $860M in October 2024 Oliver Dale | usagoldmines.com

Leave a Reply