HomeSecurityMicrosoft warns of new StilachiRAT malware

Microsoft warns of new StilachiRAT malware

This week, Microsoft published details about the StilachiRAT malware, a deceptive and persistent malware that allows cybercriminals to steal sensitive data from compromised systems.

See also: StilachiRAT: Microsoft warns of new RAT malware

StilachiRAT malware

The tech giant 's incident response team first detected StilachiRAT in November 2024. While it does not currently appear to be widespread, the company wants to warn users and organizations.

Microsoft has not yet linked the StilachiRAT malware, which has been described as a remote access tool (RAT), to any known threat group or specific country.

The company has not specified how the RAT is distributed, but said that such threats can be installed through multiple attacks, such as malware, malicious websites, and malicious emails.

Once installed on a device, the malware collects information about the system in order to achieve a detailed profile. The StilachiRAT malware then scans the system for configuration data related to 20 different cryptocurrency wallet extensions for the Chrome.

See also: Android malware OctoV2 imitates DeepSeek and steals credentials

Microsoft malware

The RAT extracts usernames and passwords stored in Chrome and constantly monitors the clipboard contents for valuable information, such as credentials and cryptocurrency keys. The malware can also monitor RDP sessions, which could allow the attacker to move horizontally within the compromised network.

According to Microsoft, the StilachiRAT malware has the ability to execute various commands, such as restarting the system, clearing logs, modifying registry entries, and running applications.

For persistence, the malware uses Windows service control management and monitoring threads to ensure that it will recover if removed. The RAT also has anti-forensics and anti-evasion capabilities.

See also: DocSwap malware disguises itself as a secure document viewer

To protect yourself from malware, such as the StilachiRAT malware, you can follow some basic and important strategies. Here are some tips:

  1. Use of reliable antivirus software
  2. Upgrading the operating system and software
  3. Avoiding suspicious links and attachments
  4. Use strong passwords and change them frequently
  5. Installing and using a firewall
  6. Avoid downloading software from unsafe sources
  7. Pay attention to privacy settings and app permissions
  8. Dealing with suspicious activities

By following these tips, you significantly reduce the risk of being affected by malware.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS