No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Crypto

Microsoft Uncovers New Crypto-Stealing Malware—Is Your Wallet at Risk?

March 19, 2025
in Crypto
0
Microsoft Uncovers New Crypto-Stealing Malware—Is Your Wallet at Risk?


Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Microsoft has identified a new remote access trojan (RAT) designed to steal cryptocurrency from users by targeting digital wallet extensions on Google Chrome.

The malware, dubbed StilachiRAT, has been under investigation since November 2024, and security experts warn it poses a significant threat to crypto holders.

How StilachiRAT Operates

According to Microsoft’s Incident Response Team, StilachiRAT is capable of extracting credentials stored in the browser, scanning devices for crypto wallet extensions, and intercepting sensitive information such as private keys and passwords.

The malware has been found to specifically target at least 20 cryptocurrency wallets, including Bitget Wallet (formerly BitKeep), Trust Wallet, Coinbase Wallet, MetaMask, TronLink and OKX Wallet. Once deployed, it can steal stored digital assets by accessing clipboard data and extracting private credentials.

Microsoft’s research indicates that StilachiRAT operates stealthily, using various evasion techniques to avoid detection. The malware installs itself through a compromised library file, WWStartupCtrl64.dll, which executes remote commands to manipulate infected systems.

Once active, it scans the device for crypto wallet extensions and extracts saved credentials from Google Chrome’s local state files. A key feature of the malware is its ability to monitor clipboard activity, meaning if users copy and paste crypto wallet addresses or passwords, StilachiRAT can capture and redirect that information to the attacker.

Microsoft also found that the trojan includes anti-forensic capabilities, such as clearing event logs and detecting sandbox environments to avoid being analyzed by cybersecurity researchers.

Microsoft’s Response and Security Recommendations

At present, Microsoft has not attributed the attack to any specific hacker group but has warned that due to the nature of the malware ecosystem, StilachiRAT could evolve rapidly.  In a blog post, the company stated:

Based on Microsoft’s current visibility, the malware does not exhibit widespread distribution at this time. However, due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings as part of our ongoing efforts to monitor, analyze, and report on the evolving threat landscape.

Microsoft advises users to take precautionary measures to avoid falling victim to StilachiRAT and similar threats. The company recommends installing antivirus software, enabling cloud-based anti-phishing and anti-malware protection, and ensuring all browser extensions come from trusted sources.

Users should also be cautious when copying and pasting wallet addresses and passwords, as malware like StilachiRAT specifically exploits clipboard data.

With increasing security risks in the crypto space, Microsoft’s warning highlights the importance of staying vigilant against cyber threats. As hackers develop more advanced techniques to compromise digital wallets, investors and everyday users must take proactive steps to secure their assets.

The global crypto market cap value on TradingView
The global digital currency market cap value on the 1-day chart. Source: TradingView.com

Featured image created with DALL-E, Chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Editorial Team

Editorial Team

Related Posts

Solana-based DeFi lender CrediX exploited; attacker granted admin access and drained liquidity pool
Crypto

Solana-based DeFi lender CrediX exploited; attacker granted admin access and drained liquidity pool

August 4, 2025
Arkham Unveiled the Largest Hack in History: Now Worth $14.5B
Crypto

Arkham Unveiled the Largest Hack in History: Now Worth $14.5B

August 3, 2025
CFTC
Crypto

CFTC Announces “Crypto Sprint”, Pledges To Support Of SEC’s Project Crypto

August 3, 2025
$3.5 Billion Bitcoin Heist, Biggest Crypto Hack Ever, Retroactively Uncovered
Crypto

$3.5 Billion Bitcoin Heist, Biggest Crypto Hack Ever, Retroactively Uncovered

August 2, 2025
Bitcoin’s era of financial infrastructure has begun
Crypto

Bitcoin’s era of financial infrastructure has begun

August 2, 2025
Trump-backed American Bitcoin nears Nasdaq listing as Gryphon merger vote set for August 27
Crypto

Trump-backed American Bitcoin nears Nasdaq listing as Gryphon merger vote set for August 27

August 1, 2025
Load More
Next Post
PitchBook private debt report

Largest managers and funds increasingly dominate private credit

Popular News

  • The 10 best banks for college students in 2025

    The 10 best banks for college students in 2025

    0 shares
    Share 0 Tweet 0
  • Solana-based DeFi lender CrediX exploited; attacker granted admin access and drained liquidity pool

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Western Union Turns Bullish on Stablecoins Amid US Regulation

    0 shares
    Share 0 Tweet 0
  • 5 Things to Know About the Lane Health Healthcare Spending Card

    0 shares
    Share 0 Tweet 0

Latest News

broker-clients

Lee Coates: A practical guide to sustainable investment conversations

August 4, 2025
0

As sustainability becomes an increasingly prominent consideration in investment decision-making, financial advisers are faced with a dual responsibility: supporting client...

Insurers can boost income and reduce correlation risk by investing in business development companies

BDCs present ‘distinct advantages’ for insurance companies

August 4, 2025
0

For insurers seeking investments in private credit, business development companies (BDCs) present “distinct advantages”, including a straightforward balance sheet treatment...

Solana-based DeFi lender CrediX exploited; attacker granted admin access and drained liquidity pool

Solana-based DeFi lender CrediX exploited; attacker granted admin access and drained liquidity pool

August 4, 2025
0

Key Takeaways CrediX suffered an exploit after an attacker gained multisig admin and bridge controller roles, draining the protocol's pool....

Land, Nature, Outdoors

8 Cheap Beach Vacation Spots

August 4, 2025
0

You could shell out thousands of dollars to stick your toes in the sand for a long weekend. Hotel rooms...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.