logo

Microsoft Sounds Warning on Multifunctional 'StilachiRAT'

ID: aa01072b-4321-56ed-9fcf-ed2dac6c24b5

STIX ID: report--aa01072b-4321-56ed-9fcf-ed2dac6c24b5

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-03-18

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

StilachiRAT is a stealthy Remote Access Trojan observed by Microsoft that bundles system reconnaissance, credential and cryptocurrency wallet theft, clipboard monitoring, and robust persistence/anti-analysis techniques (watchdog threads, service reconstruction, sandbox detection). It communicates with C2 over common ports (53, 443), delays initial contact, and targets Chrome-stored credentials and up to 20 wallet extensions; Microsoft recommends EDR in block mode, Safe Links/Attachments, Defender PUA protections, and using browsers that block malicious sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.