logo

Microsoft Warns of New StilachiRAT Stealing Remote Desktop Protocol Sessions Data

ID: 125e6562-8fd2-5e90-af4e-0033636244ef

STIX ID: report--125e6562-8fd2-5e90-af4e-0033636244ef

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-03-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Microsoft alerts to StilachiRAT, a sophisticated RAT that hijacks Windows RDP sessions to capture credentials, keystrokes and full session recordings; it achieves persistence via scheduled tasks and registry changes, exfiltrates data over encrypted DNS tunneling and HTTPS callbacks, employs VM/debugger evasion and API hooking inside mstsc.exe, and has been used in targeted campaigns against financial, government, and critical infrastructure organizations — recommended mitigations include MFA for RDP, restricting access, patching, EDR capable of detecting API hooks, and monitoring for unusual RDP activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.