Microsoft security researchers have disclosed a new remote access trojan (RAT) named StilachiRAT, first observed in November 2024, that is specifically designed to steal credentials and cryptocurrency wallet data from compromised Windows systems. According to Microsoft’s analysis, the malware performs extensive system reconnaissance, collects browser-stored passwords, monitors clipboard contents, and then scans Chrome profile data for configuration files associated with around 20 crypto wallet extensions, including popular wallets such as MetaMask, Phantom, Trust Wallet, OKX Wallet, Sui Wallet, Coinbase Wallet, and Keplr. Once it finds these wallets, StilachiRAT attempts to extract and decrypt sensitive information that could enable threat actors to take over accounts and drain funds.
Beyond data theft, StilachiRAT maintains a persistent foothold and remote control over infected hosts via a command‑and‑control (C2) server, allowing attackers to execute commands, launch programs, manage services, monitor RDP sessions, and erase logs to hinder forensic analysis. Microsoft notes that the malware has not yet been distributed at large scale but uses advanced evasion techniques, including checks for sandboxes and analysis tools, making it harder to detect with standard defenses. Security advisories from Microsoft and other vendors emphasize hardening basic practices—such as avoiding storage of critical credentials in browsers, reviewing and limiting installed wallet extensions, and keeping endpoint protection and patching regimes up to date—because successful compromise can expose both crypto assets and broader account access across a victim’s digital footprint.
✨ AI-generated background, compiled from web sources — not editorial content.