New Trojan Malware StilachiRAT Targets Crypto Browser Wallets, Microsoft Warns
First detected in November 2024, this malware employs advanced techniques to evade detection, maintain persistence, and exfiltrate sensitive data from compromised systems. Notably, it specifically targets cryptocurrency...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
First detected in November 2024, this malware employs advanced techniques to evade detection, maintain persistence, and exfiltrate sensitive data from compromised systems.
Notably, it specifically targets cryptocurrency assets by scanning for configuration data of 20 different wallet extensions within the Google Chrome browser. These targeted wallets include MetaMask, Trust Wallet, Coinbase Wallet, Phantom Wallet, BNB Chain Wallet, OKX Wallet, and others.
Capabilities and Targets
StilachiRAT is designed to conduct extensive system reconnaissance, collecting information such as operating system details, hardware identifiers, BIOS serial numbers, camera presence, active Remote Desktop Protocol (RDP) sessions, and running graphical user interface applications.
In addition to cryptocurrency theft, StilachiRAT can extract and decrypt credentials stored in Google Chrome, monitor clipboard content for sensitive data such as passwords and cryptocurrency keys, and track active windows and applications. The malware also monitors RDP sessions by capturing foreground window information and duplicating security tokens to impersonate users, potentially facilitating lateral movement within networks.
Persistence and Evasion Techniques
To maintain persistence, StilachiRAT can operate either as a Windows service or a standalone component, employing watchdog threads that monitor its presence and recreate its files if they are removed. The malware establishes communication with its command-and-control (C2) servers using commonly used TCP ports like 53 and 443, allowing it to receive commands such as system reboots, log clearing, registry manipulation, application execution, and system suspension.
Microsoft says StilachiRAT employs various anti-forensic and evasion tactics, including clearing event logs to erase evidence, detecting forensic tools and virtual machines to avoid analysis, and implementing sandbox-evading behaviors to prevent detection. These stealthy approaches make it difficult to detect and remove once a system is compromised.
Mitigation Strategies
To protect against StilachiRAT, security experts recommend several measures:
-
Keep software and operating systems updated: Regularly apply patches to address known vulnerabilities.
-
Use reputable security software: Implement comprehensive security solutions that include antivirus and endpoint detection and response capabilities.
-
Enable Multi-Factor Authentication (MFA): Adding an extra layer of security can prevent unauthorized access.
-
Exercise caution with downloads and links: Avoid unverified downloads and be wary of clicking on suspicious links.
-
Monitor system logs: Regularly review logs for unauthorized changes or unusual activity.
For cryptocurrency users, it is particularly important to be aware of the risks associated with browser-based wallets, which store private keys in software and are vulnerable to malware attacks.
Security experts emphasize that the safest way to protect crypto holdings is to store private keys in a hardware wallet or with a qualified custodian. Unlike software-based wallets, hardware wallets store private keys in a secure chip, require physical confirmation for transactions, and are immune to clipboard hijacking and keylogging attacks.
Why this matters
This research story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Brave New CoinRelated market context
SafePal Data Breach Exposes 39,798 Crypto Customers, Wallet Keys Remain Secure
Key Takeaways: About 39,798 users’ personal and purchase information were disclosed via a flaw in an order tracking plugin, accord...
Bitcoin purchases halted after data breach puts 250,000 crypto users at risk
Israel’s largest regulated cryptocurrency broker, Bits of Gold, is investigating a data breach that potentially exposed the person...
Dynamic SDK V5 launches with TSS-MPC for enhanced wallet security
Dynamic SDK V5's TSS-MPC enhances crypto wallet security, reducing risks of key theft and improving user recovery options across m...
Crypto wallet SafePal reveals a data breach exposing nearly 40,000 customers' order info
While the data breach exposed the personal order details of thousands of customers, all private keys, seed phrases, and crypto ass...
SafePal Bitcoin Wallet Data Breach Stokes Fears of Physical Attacks
A flaw in an order-tracking plug-in of bitcoin wallet provider SafePal exposed names, addresses and phone numbers of nearly 40,000...
Bits of Gold Breach May Expose 200,000 Crypto Users, But Funds Remain Safe Online
Key Takeaways: A data breach at Bits of Gold could affect up to 200,000 customers. No exposure of customer funds, crypto assets, p...