โ ๏ธ Warning: Microsoft has identified a new remote access trojan (RAT) named StilachiRAT ๐ฆ , designed to infiltrate Google Chrome and steal cryptocurrency wallets. ๐ฅ
๐ Discovered in November 2024, this malware poses a serious threat to crypto users by stealing sensitive information and maintaining persistent access to infected systems. โ ๏ธ
---
๐ฏ Targeted Cryptocurrency Wallet Extensions
StilachiRAT specifically aims at 20+ cryptocurrency wallet extensions within Chrome, including:
๐น MetaMask ๐ฆ
๐น Coinbase Wallet ๐ฐ
๐น Trust Wallet ๐
๐น OKX Wallet ๐ฆ
๐น Bitget Wallet ๐
๐น Phantom ๐ป
๐น TronLink โก
๐น ConfluxPortal ๐
๐จ Once compromised, it can steal:
๐ Login credentials
๐ Private keys
๐ Clipboard data
---
โ ๏ธ StilachiRAT's Dangerous Capabilities
๐ Information Gathering ๐ต๏ธโโ๏ธ
Collects system details, camera status ๐ท, active remote sessions, and running applications ๐.
โ๏ธ Clipboard Monitoring ๐
Captures copied passwords and crypto keys ๐ดโโ ๏ธ.
๐ฅ๏ธ Remote Command Execution ๐ป
Can reboot the system, launch applications, and delete logs ๐๏ธ.
๐ Self-Reinstall Mechanism ๐ก๏ธ
If deleted, it reinstalls itself automatically โ๏ธ!
---
๐ก๏ธ How to Stay Safe from StilachiRAT?
โ Only download software from official sources ๐ฅ
โ Use trusted antivirus programs ๐ก๏ธ
โ Enable cloud-based security features โ๏ธ
โ Be cautious with emails & links ๐ง๐ซ
๐ Stay vigilant and secure your crypto assets! ๐๐ฐ
