{"id":17992,"date":"2025-03-19T05:02:23","date_gmt":"2025-03-19T05:02:23","guid":{"rendered":"https:\/\/dogewisperer.com\/?p=17992"},"modified":"2025-03-19T05:02:23","modified_gmt":"2025-03-19T05:02:23","slug":"microsoft-uncovers-new-crypto-stealing-malware-is-your-wallet-at-risk","status":"publish","type":"post","link":"https:\/\/dogewisperer.com\/?p=17992","title":{"rendered":"Microsoft Uncovers New Crypto-Stealing Malware\u2014Is Your Wallet at Risk?"},"content":{"rendered":"<div>\n<p data-pm-slice=\"1 1 []\">Microsoft has <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/03\/17\/stilachirat-analysis-from-system-reconnaissance-to-cryptocurrency-theft\/\" target=\"_blank\" rel=\"noopener nofollow\">identified<\/a> a new remote access trojan (RAT) designed to steal cryptocurrency from users by targeting digital wallet extensions on Google Chrome.<\/p>\n<p data-pm-slice=\"1 1 []\">The malware, dubbed StilachiRAT, has been under investigation since November 2024, and security experts warn it poses a significant threat to crypto holders.<\/p>\n<h2 data-pm-slice=\"1 1 []\">How StilachiRAT Operates<\/h2>\n<p>According to Microsoft\u2019s Incident Response Team, StilachiRAT is capable of extracting credentials stored in the browser, scanning devices for crypto wallet extensions, and intercepting sensitive information such as private keys and passwords.<\/p>\n<p>The malware has been found to specifically target at least 20 cryptocurrency wallets, including Bitget Wallet (formerly BitKeep), Trust Wallet, Coinbase Wallet, MetaMask, TronLink and OKX Wallet. Once deployed, it can steal stored digital assets by accessing clipboard data and extracting private credentials.<\/p>\n<p data-pm-slice=\"1 1 []\">Microsoft\u2019s research indicates that StilachiRAT <a href=\"https:\/\/bitcoinist.com\/bitcoin-crypto-will-not-recover-before-us-equities\/\" target=\"_blank\" rel=\"noopener \">operates stealthily<\/a>, using various evasion techniques to avoid detection. The malware installs itself through a compromised library file, WWStartupCtrl64.dll, which executes remote commands to manipulate infected systems.<\/p>\n<p data-pm-slice=\"1 1 []\">Once active, it scans the device for crypto wallet extensions and extracts saved credentials from Google Chrome\u2019s local state files. A key feature of the malware is its ability to monitor clipboard activity, meaning if users copy and paste <a href=\"https:\/\/bitcoinist.com\/crypto-market-peak-stablecoin-supply-surge-shows-theres-more-room-to-grow\/\" target=\"_blank\" rel=\"noopener \">crypto wallet addresses<\/a> or passwords, StilachiRAT can capture and redirect that information to the attacker.<\/p>\n<p data-pm-slice=\"1 1 []\">Microsoft also found that the trojan includes anti-forensic capabilities, such as clearing event logs and detecting sandbox environments to avoid being analyzed by cybersecurity researchers.<\/p>\n<h2 data-pm-slice=\"1 1 []\">Microsoft\u2019s Response and Security Recommendations<\/h2>\n<p>At present, Microsoft has not attributed the attack to any specific hacker group but has warned that due to the nature of the malware ecosystem, StilachiRAT could <a href=\"https:\/\/bitcoinist.com\/best-crypto-to-buy-now-as-trumps-world-liberty-financial-raises-590m\/\" target=\"_blank\" rel=\"noopener \">evolve rapidly<\/a>. \u00a0In a blog post, the company stated:<\/p>\n<blockquote>\n<p>Based on Microsoft\u2019s current visibility, the malware does not exhibit widespread distribution at this time. However, due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings as part of our ongoing efforts to monitor, analyze, and report on the evolving threat landscape.<\/p>\n<\/blockquote>\n<p>Microsoft advises users to take precautionary measures to avoid falling victim to StilachiRAT and similar threats. The company recommends<a href=\"https:\/\/bitcoinist.com\/aml-bitcoin-creator-convicted-of-wire-fraud-and-money-laundering\/\" target=\"_blank\" rel=\"noopener \"> installing antivirus software<\/a>, enabling cloud-based anti-phishing and anti-malware protection, and ensuring all browser extensions come from trusted sources.<\/p>\n<p>Users should also be cautious when copying and pasting wallet addresses and passwords, as malware like StilachiRAT specifically exploits clipboard data.<\/p>\n<p data-pm-slice=\"1 1 []\">With increasing security risks in the crypto space, Microsoft\u2019s warning highlights the importance of staying vigilant against cyber threats. As hackers develop more<a href=\"https:\/\/bitcoinist.com\/crypto-podcaster-jailed-for-45-months-in-fraud\/\" target=\"_blank\" rel=\"noopener \"> advanced techniques<\/a> to compromise digital wallets, investors and everyday users must take proactive steps to secure their assets.<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"size-medium\" src=\"https:\/\/www.tradingview.com\/x\/8yIw1Y6U\/\" alt=\"The global crypto market cap value on TradingView\" width=\"3250\" height=\"1794\"><\/p>\n<p data-pm-slice=\"1 1 []\">Featured image created with DALL-E, Chart from TradingView<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has identified a new remote access trojan (RAT) designed to steal cryptocurrency from users by targeting digital wallet extensions on Google Chrome. The malware, dubbed StilachiRAT, has been under investigation since November 2024, and security experts warn it poses a significant threat to crypto holders. How StilachiRAT Operates According to Microsoft\u2019s Incident Response Team, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"footnotes":""},"categories":[2],"tags":[3,4,5],"class_list":["post-17992","post","type-post","status-publish","format-standard","hentry","category-news","tag-crypto","tag-doge","tag-news"],"_links":{"self":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/17992","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17992"}],"version-history":[{"count":0,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=\/wp\/v2\/posts\/17992\/revisions"}],"wp:attachment":[{"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dogewisperer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}