|
Microsoft flags new remote access trojan targeting crypto wallet extensions on Chrome browser - TechAmok
Microsoft flags new remote access trojan targeting crypto wallet extensions on Chrome browser - [security] 06:05 PM EDT - Mar,18 2025 - post a comment Microsoft has discovered a new trojan, StilachiRAT, targeting cryptocurrency wallets in the Google Chrome browser.
The malware attacks 20 different extensions, including MetaMask, Coinbase Wallet, Trust Wallet, OKX Wallet, Bitget Wallet, Phantom, and more
StilachiRAT surfaced in November 2024 but does not appear to be widely distributed so far. However, its stealth capabilities make it a potent threat that enterprise security teams need to be aware of and protect against, Microsoft warned this week. "Microsoft continues to monitor information on the delivery vector used in these attacks," the company noted. "Malware like StilachiRAT can be installed through multiple vectors; therefore, it is critical to implement security-hardening measures to prevent the initial compromise."
StilachiRAT is a veritable Swiss Army knife for hackers. It can collect wide-ranging data like OS details, hardware identifiers including BIOS serial numbers, camera presence, and active remote desktop protocol (RDP) sessions from the system on which it is installed.
The malware is enabled for credential theft and can extract and decrypt usernames and passwords stored in Google Chrome. It targets cryptocurrency assets by scanning for as many as 20 wallet extensions within the Chrome browser. The wallets in its target list include Coinbase, Fractal, Phantom, Manta, and Bitget. In addition, the malware continuously collects clipboard content and monitors active applications, specifically targeting sensitive data such as passwords and cryptocurrency keys.
StilachiRAT is stealthy. The malware communicates with its command-and-control (C2) servers through commonly used TCP ports like Port 53, typically associated with DNS traffic, and 443, the standard port for HTTPS traffic. Both are ports that malware tools frequently use to hide malicious activity and receive commands from a C2 server. In the case of StilachiRAT, the commands it can act upon include system reboots, registry manipulation, log clearing, and executing additional malicious payloads.
|
|
Add your comment (free registrationrequired)
Short overview of recent news articles |
Sep,06 2025 You can't download and install Windows 11 25H2 yet as Microsoft Sep,04 2025 A House of Dynamite - Official Teaser (2025) Rebecca Ferguson, Greta Sep,04 2025 RTX 5060 Ti 16GB + Ryzen 5 5600 : Test in 17 Games Sep,02 2025 BUGONIA Trailer 2 (2025) Emma Stone, Jesse Plemons Sep,02 2025 Huawei unveils world-leading AI supercharged hard drive to power Sep,01 2025 AM4 Lives: AMD Ryzen 5 5500X3D CPU Review & Benchmarks Aug,29 2025 I was wrong, iPhone IS better than Android...- 30 Day iPhone Aug,29 2025 303KM/H BMW X5 M50i GPOWER SOUNDS LIKE THUNDER Aug,29 2025 NVIDIA GeForce 581.15 WHQL drivers Aug,28 2025 Apple Intelligence vs Galaxy AI / Google Pixel AI / Xiaomi HyperAI - Aug,28 2025 The Woman in Cabin 10 - Official Trailer Aug,28 2025 YANGWANG U9 Breaks Global EV Top Speed Record Aug,26 2025 AMD B850 Motherboard Roundup: Sub $200 Models Aug,25 2025 Gamers Nexus: Our Channel Could Be Deleted Aug,24 2025 2025 Audi A5 E-Hybrid 299HP "250KMH is back!!" // REVIEW on Aug,23 2025 I Can't Stop You From Buying This... But I'll Try - GeForce RTX Aug,23 2025 NVIDIA GeForce 581.08 WHQL Driver Aug,21 2025 Murcielago with flames chasing an F1 car on highway (2025) Aug,18 2025 Windows 11 24H2 Security Update Causes SSD/HDD Failures and Aug,17 2025 Samsung Galaxy Z Fold 7 - Tips, Tricks & Hidden Features! Aug,17 2025 500Hz OLEDs are Awesome - Gigabyte AORUS FO27Q5P Review Aug,17 2025 They Said my Gaming & Badminton Club Would Never OPEN! Aug,13 2025 NVIDIA GeForce Game Ready 580.97 WHQL Driver Aug,13 2025 When your Bro needs a new computer... Aug,12 2025 WhatsApp's latest update is a huge "convenience" for group chats Aug,12 2025 COLLAPSE: Intel is Falling Apart Aug,11 2025 Useless or Genius: NVMe SSD Coolers Aug,11 2025 2025 NEW! Audi A6 3.0 TFSI - BETTER than BMW 5? / Aug,10 2025 Ryzen 7 5800X3D vs. 9800X3D, Battlefield 6 Open Beta Benchmark Aug,10 2025 How to Enter BIOS from Windows Using CMD | Easiest Method (No Key Aug,09 2025 Battlefield 6 Open Beta Benchmark: 9800X3D vs. 9700X vs. 265K Aug,09 2025 WhatsApp finally adds a useful photo feature for Android users Aug,09 2025 OpenAI announces ChatGPT changes following user feedback Aug,06 2025 Corsair MAKR75 Review - Ultimate DIY Keyboard Kit Aug,06 2025 1176 Hardware vs Plugin - Is There Really a Difference? Aug,06 2025 Do this NOW: Use Disposable Windows for Maximum Security! Aug,06 2025 CPU/GPU Scaling: Ryzen 7 5800X3D (RTX 5090, 5080, RX 9070 & 9060 XT) Aug,05 2025 XRP To $1000 By 2030... Know What You Hold BUT SELL YOUR XRP HERE: ? Aug,03 2025 NURBURGRING HEAVY RAINSTORM! MANY Fails, Spins & Slippery Action! Aug,03 2025 2025 Bentley Continental GTC SPEED // REVIEW on AUTOBAHN
>> News Archive <<
| |
|