BlockNews
FOLLOW ON X
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • SUI
    • CHAINLINK
    • LITECOIN
  • FINANCE
  • POLITICS
  • MEMECOINS
  • NFT
  • OPINION
No Result
View All Result
BlockNews
Home CRYPTO

Crypto Hack Alert: Microsoft Warns of StilachiRAT Malware Targeting Crypto Wallets

Michael Juanico by Michael Juanico
March 18, 2025
in CRYPTO, FINANCE, TECHNOLOGY
Share on XShare in TelegramShare on Reddit
  • StilachiRAT is a stealthy malware that steals credentials, crypto wallets, and system data while evading detection.
  • It can execute remote commands, wipe event logs, and even shut down infected systems.
  • Palo Alto Networks uncovered additional threats, including an IIS backdoor, a bootkit, and a post-exploitation framework.

Microsoft is sounding the alarm on a newly uncovered remote access trojan (RAT) dubbed StilachiRAT—an elusive piece of malware built to dodge detection, dig in deep, and siphon sensitive data straight from infected systems.

🚨 ALERT: Microsoft has identified a remote access trojan (RAT) named 'StilachiRAT' which is capable of stealing crypto wallet data pic.twitter.com/doHCSxhhgm

— BlockNews (@blocknewsdotcom) March 18, 2025

What is StilachiRAT?

According to the Microsoft Incident Response team, StilachiRAT is designed to steal everything from browser-stored credentials to digital wallet info, clipboard data, and detailed system information. The malware, first spotted in November 2024, operates via a DLL module called “WWStartupCtrl64.dll.”

So far, no specific hacker group or nation has been linked to its development. Microsoft hasn’t confirmed how it spreads, but common delivery methods for such trojans include phishing emails, malicious downloads, or exploited vulnerabilities. The bottom line? Organizations need to stay ahead of the game with strong security protocols.

How Does StilachiRAT Work?

This RAT goes all-in on system reconnaissance. It collects OS details, BIOS serial numbers, camera presence, active Remote Desktop Protocol (RDP) sessions, and even running GUI applications. Using Component Object Model (COM) and WMI Query Language (WQL), it methodically pulls system data without raising red flags.

One of its more alarming features is its focus on cryptocurrency wallets. StilachiRAT scans for wallet extensions in Google Chrome, specifically targeting major players like MetaMask, Trust Wallet, Coinbase Wallet, Phantom, TronLink, and several others. Once inside, it doesn’t just steal credentials—it also lifts clipboard content, watches RDP sessions, and beams the stolen data back to its remote command-and-control (C2) server.

A Multi-Purpose Espionage Tool

The malware’s C2 connection isn’t just for data theft; it allows remote operators to execute commands in real-time. Microsoft has identified at least 10 different functions StilachiRAT can perform:

  • Display an HTML-rendered dialog box from a supplied URL (Command 07)
  • Wipe event logs to erase forensic traces (Command 08)
  • Shut down the system using an undocumented Windows API (Command 09)
  • Establish outbound or inbound network connections (Commands 13 & 14)
  • Terminate active network connections (Command 15)
  • Launch applications remotely (Command 16)
  • Scan open windows for specific title bar text (Command 19)
  • Put the system into sleep or hibernation mode (Command 26)
  • Steal Chrome passwords outright (Command 30)

To evade detection, StilachiRAT employs anti-forensic techniques, including event log clearing and sandbox evasion—constantly checking for analysis tools before fully activating.

The Bigger Cybersecurity Picture

This disclosure comes as Palo Alto Networks’ Unit 42 reports three more unusual malware strains circulating in the wild:

  • An IIS backdoor that parses incoming HTTP requests and executes embedded commands.
  • A bootkit that installs a GRUB 2 bootloader through an unsecured kernel driver (potentially a prank, as it plays Dixie through the PC speaker upon reboot).
  • A Windows implant of ProjectGeass, a sophisticated post-exploitation framework.

These discoveries highlight the increasing sophistication of cyber threats. As attackers refine their techniques, organizations must stay proactive—because once malware like StilachiRAT burrows in, it doesn’t let go easily.

Disclaimer: BlockNews provides independent reporting on crypto, blockchain, and digital finance. All content is for informational purposes only and does not constitute financial advice. Readers should do their own research before making investment decisions. Some articles may use AI tools to assist in drafting, but every piece is reviewed and edited by our editorial team of experienced crypto writers and analysts before publication.
Tags: Microsoftremote access trojanStilachiRAT
Tweet2ShareShare
Michael Juanico

Michael Juanico

Michael is a BSBA Management graduate from Mindanao State University and has been a professional content writer since 2019. He began exploring cryptocurrency in 2021 and has since made blockchain and digital assets his primary focus. For nearly four years, Michael has contributed research and editorial content at Aiur Labs and BlockNews, producing clear and accessible coverage of market trends, trading strategies, and project developments. He is transparent about his personal holdings in Bitcoin, TRON, and select meme tokens, combining writing expertise with hands-on market experience to deliver trustworthy insights to readers.

DON'T MISS THESE! HOT OFF THE PRESS

Bitmine Expands Massive Ethereum Treasury – Here Is Why the ETH Bet Matters
CRYPTO

Bitmine Expands Massive Ethereum Treasury – Here Is Why the ETH Bet Matters

March 9, 2026
Strategy Buys $1.3B More Bitcoin – Here Is Why the MSTR BTC Bet Keeps Growing
BITCOIN

Strategy Buys $1.3B More Bitcoin – Here Is Why the MSTR BTC Bet Keeps Growing

March 9, 2026
Bank of Canada’s Tokenized Bond Trial Quietly Signals Where Global Finance Is Headed Next
CRYPTO

Bank of Canada’s Tokenized Bond Trial Quietly Signals Where Global Finance Is Headed Next

March 9, 2026
Shiba Inu Investor Growth Slows – Here Is Why SHIB Adoption Is Stalling
CRYPTO

Shiba Inu Investor Growth Slows – Here Is Why SHIB Adoption Is Stalling

March 9, 2026
Banks Need the Digital Asset Clarity Act More Than Crypto — And Wall Street Knows It
CRYPTO

Banks Need the Digital Asset Clarity Act More Than Crypto — And Wall Street Knows It

March 9, 2026
Nasdaq’s 24/7 Tokenized Stock Plan With Kraken Signals the Slow Death of Wall Street’s 9-to-5
CRYPTO

Nasdaq’s 24/7 Tokenized Stock Plan With Kraken Signals the Slow Death of Wall Street’s 9-to-5

March 9, 2026
Load More

Related News

Bitmine Expands Massive Ethereum Treasury – Here Is Why the ETH Bet Matters

Bitmine Expands Massive Ethereum Treasury – Here Is Why the ETH Bet Matters

March 9, 2026
Strategy Buys $1.3B More Bitcoin – Here Is Why the MSTR BTC Bet Keeps Growing

Strategy Buys $1.3B More Bitcoin – Here Is Why the MSTR BTC Bet Keeps Growing

March 9, 2026
Bank of Canada’s Tokenized Bond Trial Quietly Signals Where Global Finance Is Headed Next

Bank of Canada’s Tokenized Bond Trial Quietly Signals Where Global Finance Is Headed Next

March 9, 2026
Shiba Inu Investor Growth Slows – Here Is Why SHIB Adoption Is Stalling

Shiba Inu Investor Growth Slows – Here Is Why SHIB Adoption Is Stalling

March 9, 2026
Banks Need the Digital Asset Clarity Act More Than Crypto — And Wall Street Knows It

Banks Need the Digital Asset Clarity Act More Than Crypto — And Wall Street Knows It

March 9, 2026
Twitter Telegram Threads

BLOCKNEWS.COM

BlockNews is your premier source for real-time cryptocurrency, blockchain, political and financial market news.

Stay ahead of the herd with BlockNews

RESOURCES

  • About Us
  • Contact Us
  • Editorial Policies
  • Terms and Conditions
  • Privacy Policy
  • Sitemap

DISCLOSURES AND POLICIES

BlockNews provides independent reporting on crypto, blockchain, and digital finance. Content is for informational purposes only and does not constitute financial advice. Sponsored material is always disclosed. By using this site, you agree to our Terms and Conditions and Privacy Policy.

© 2025 BlockNews

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO
    • ETHEREUM
    • RIPPLE XRP
    • SOLANA
    • CARDANO
    • BINANCE BNB
    • DOGECOIN
    • TRON
    • LITECOIN
    • CHAINLINK
    • SUI
  • MEMECOINS
  • POLITICS
  • FINANCE
  • NFT
  • DEFI
  • GUIDES

© 2025 BlockNews