HomeSecurityStilachiRAT: Microsoft warns of new RAT malware

StilachiRAT: Microsoft warns of new RAT malware

Microsoft has discovered a new remote access trojan (RAT), dubbed StilachiRAT, that uses “sophisticated techniques” to evade detection, maintain persistence on compromised systems, and steal sensitive data.

StilachiRAT malware Microsoft

At present, the malware is not widely distributed, but Microsoft says it has decided to publicly share breach indicators and some protection tips to help network defenders identify this threat and mitigate its impact.

Due to limited incidents, Microsoft has not yet attributed StilachiRAT to a specific threat actor.

According to Microsoft, the WWStartupCtrl64.dll module of StilachiRAT contains the RAT capabilities. An analysis of it revealed the use of various methods to steal information, such as credentials stored in the browser, digital wallet information, data stored in the clipboard , and system information.

See also: Android malware OctoV2 imitates DeepSeek and steals credentials

Furthermore, StilachiRAT is equipped with powerful reconnaissance, which allow it to collect system data (e.g. hardware identifiers, camera presence, active Remote Desktop Protocol (RDP) sessions, and execution of GUI-based applications).

After deployment to a system, attackers can use StilachiRAT to steal digital wallet data by scanning the configuration information of 20 crypto wallet, including Coinbase Wallet, Phantom, Trust Wallet, Metamask, OKX Wallet, Bitget Wallet, and others.

The malware also steals credentials stored in Google Chrome's local state file and monitors clipboard activity for sensitive information (e.g. passwords and cryptocurrency keys), while monitoring active windows and applications.

Once launched as a standalone process or Windows service, the RAT gains and maintains persistence through the Windows Service Control Manager (SCM) and ensures that it will automatically reinstall itself using watchdog threads that monitor the malware and recreate them if they are no longer active.

See also: Phishing emails imitate Booking.com and distribute malware

As previously mentioned, StilachiRAT can also actively monitor RDP sessions, taking information from foreground windows and cloning security tokens to impersonate logged-in users. Through this method, attackers can spread to victim networks after deploying the RAT to RDP servers.

Microsoft researchers also noted that the malware is equipped with features that allow it to effectively evade detection. For example, there is a feature that clears event logs and another that checks for evidence of sandboxing. However, even when executed in a sandbox, StilachiRAT's Windows API calls are further coded and obfuscated to slow down analysis.

StilachiRAT: Microsoft warns of new RAT malware

Last but not least, StilachiRAT allows command execution and possible SOCKS-like proxying using commands from a command and control (C2) server. Based on these commands, attackers can reboot or suspend the compromised system, delete log files, steal credentials, execute applications, manipulate system windows, and modify Windows registry values.

Microsoft recommends downloading software only from official websites and using security software that can block malicious domains and email attachments.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.

See also: DocSwap malware disguises itself as a secure document viewer

You should also be careful with emails and messages you receive. Many RAT malware are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks . Using two-factor authentication can also add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS