Microsoft Warns of New StilachiRAT Stealing Remote Desktop Protocol Sessions Data
ID: 125e6562-8fd2-5e90-af4e-0033636244ef
STIX ID: report--125e6562-8fd2-5e90-af4e-0033636244ef
Feed Name: cybersecurityNews.com
Microsoft alerts to StilachiRAT, a sophisticated RAT that hijacks Windows RDP sessions to capture credentials, keystrokes and full session recordings; it achieves persistence via scheduled tasks and registry changes, exfiltrates data over encrypted DNS tunneling and HTTPS callbacks, employs VM/debugger evasion and API hooking inside mstsc.exe, and has been used in targeted campaigns against financial, government, and critical infrastructure organizations — recommended mitigations include MFA for RDP, restricting access, patching, EDR capable of detecting API hooks, and monitoring for unusual RDP activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
