/?pid=25449

Updated:08:14 AM EDT Sep 06


this is ggmania.com subsite Microsoft flags new remote access trojan targeting crypto wallet extensions on Chrome browser - TechAmok

Microsoft flags new remote access trojan targeting crypto wallet extensions on Chrome browser - [security]
06:05 PM EDT - Mar,18 2025 - post a comment

Microsoft has discovered a new trojan, StilachiRAT, targeting cryptocurrency wallets in the Google Chrome browser. The malware attacks 20 different extensions, including MetaMask, Coinbase Wallet, Trust Wallet, OKX Wallet, Bitget Wallet, Phantom, and more
StilachiRAT surfaced in November 2024 but does not appear to be widely distributed so far. However, its stealth capabilities make it a potent threat that enterprise security teams need to be aware of and protect against, Microsoft warned this week. "Microsoft continues to monitor information on the delivery vector used in these attacks," the company noted. "Malware like StilachiRAT can be installed through multiple vectors; therefore, it is critical to implement security-hardening measures to prevent the initial compromise."

StilachiRAT is a veritable Swiss Army knife for hackers. It can collect wide-ranging data like OS details, hardware identifiers including BIOS serial numbers, camera presence, and active remote desktop protocol (RDP) sessions from the system on which it is installed.

The malware is enabled for credential theft and can extract and decrypt usernames and passwords stored in Google Chrome. It targets cryptocurrency assets by scanning for as many as 20 wallet extensions within the Chrome browser. The wallets in its target list include Coinbase, Fractal, Phantom, Manta, and Bitget. In addition, the malware continuously collects clipboard content and monitors active applications, specifically targeting sensitive data such as passwords and cryptocurrency keys.

StilachiRAT is stealthy. The malware communicates with its command-and-control (C2) servers through commonly used TCP ports like Port 53, typically associated with DNS traffic, and 443, the standard port for HTTPS traffic. Both are ports that malware tools frequently use to hide malicious activity and receive commands from a C2 server. In the case of StilachiRAT, the commands it can act upon include system reboots, registry manipulation, log clearing, and executing additional malicious payloads.


Add your comment (free registrationrequired)

Short overview of recent news articles

Sep,06 2025 You can't download and install Windows 11 25H2 yet as Microsoft
Sep,04 2025 A House of Dynamite - Official Teaser (2025) Rebecca Ferguson, Greta
Sep,04 2025 RTX 5060 Ti 16GB + Ryzen 5 5600 : Test in 17 Games
Sep,02 2025 BUGONIA Trailer 2 (2025) Emma Stone, Jesse Plemons
Sep,02 2025 Huawei unveils world-leading AI supercharged hard drive to power
Sep,01 2025 AM4 Lives: AMD Ryzen 5 5500X3D CPU Review & Benchmarks
Aug,29 2025 I was wrong, iPhone IS better than Android...- 30 Day iPhone
Aug,29 2025 303KM/H BMW X5 M50i GPOWER SOUNDS LIKE THUNDER
Aug,29 2025 NVIDIA GeForce 581.15 WHQL drivers
Aug,28 2025 Apple Intelligence vs Galaxy AI / Google Pixel AI / Xiaomi HyperAI -
Aug,28 2025 The Woman in Cabin 10 - Official Trailer
Aug,28 2025 YANGWANG U9 Breaks Global EV Top Speed Record
Aug,26 2025 AMD B850 Motherboard Roundup: Sub $200 Models
Aug,25 2025 Gamers Nexus: Our Channel Could Be Deleted
Aug,24 2025 2025 Audi A5 E-Hybrid 299HP "250KMH is back!!" // REVIEW on
Aug,23 2025 I Can't Stop You From Buying This... But I'll Try - GeForce RTX
Aug,23 2025 NVIDIA GeForce 581.08 WHQL Driver
Aug,21 2025 Murcielago with flames chasing an F1 car on highway (2025)
Aug,18 2025 Windows 11 24H2 Security Update Causes SSD/HDD Failures and
Aug,17 2025 Samsung Galaxy Z Fold 7 - Tips, Tricks & Hidden Features!
Aug,17 2025 500Hz OLEDs are Awesome - Gigabyte AORUS FO27Q5P Review
Aug,17 2025 They Said my Gaming & Badminton Club Would Never OPEN!
Aug,13 2025 NVIDIA GeForce Game Ready 580.97 WHQL Driver
Aug,13 2025 When your Bro needs a new computer...
Aug,12 2025 WhatsApp's latest update is a huge "convenience" for group chats
Aug,12 2025 COLLAPSE: Intel is Falling Apart
Aug,11 2025 Useless or Genius: NVMe SSD Coolers
Aug,11 2025 2025 NEW! Audi A6 3.0 TFSI - BETTER than BMW 5? /
Aug,10 2025 Ryzen 7 5800X3D vs. 9800X3D, Battlefield 6 Open Beta Benchmark
Aug,10 2025 How to Enter BIOS from Windows Using CMD | Easiest Method (No Key
Aug,09 2025 Battlefield 6 Open Beta Benchmark: 9800X3D vs. 9700X vs. 265K
Aug,09 2025 WhatsApp finally adds a useful photo feature for Android users
Aug,09 2025 OpenAI announces ChatGPT changes following user feedback
Aug,06 2025 Corsair MAKR75 Review - Ultimate DIY Keyboard Kit
Aug,06 2025 1176 Hardware vs Plugin - Is There Really a Difference?
Aug,06 2025 Do this NOW: Use Disposable Windows for Maximum Security!
Aug,06 2025 CPU/GPU Scaling: Ryzen 7 5800X3D (RTX 5090, 5080, RX 9070 & 9060 XT)
Aug,05 2025 XRP To $1000 By 2030... Know What You Hold BUT SELL YOUR XRP HERE: ?
Aug,03 2025 NURBURGRING HEAVY RAINSTORM! MANY Fails, Spins & Slippery Action!
Aug,03 2025 2025 Bentley Continental GTC SPEED // REVIEW on AUTOBAHN
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs