Microsoft’s Incident Response team has identified a remote access trojan that employs advanced techniques to steal information and evade detection.
StilachiRAT scans data from 20 cryptocurrency wallet extensions in Chrome, prompting recommendations to switch to Microsoft Edge for better security.
Microsoft’s Incident Response team has identified a new remote access trojan (RAT) named StilachiRAT, which specifically targets Google Chrome users. This malware focuses on cryptocurrency wallet extensions, accessing Windows registry key settings to check for their presence, and potentially compromising users’ digital assets.
StilachiRAT has been observed targeting several popular crypto wallets, including Bitget Wallet (formerly BitKeep), Trust Wallet, The OKX Wallet, BNB Chain Wallet, Coinbase Wallet, and TronLink. The malware locates these wallets by scanning for their Chrome extension identifiers. If it detects any of these extensions, it may attempt to manipulate or steal crypt