logo

Microsoft: New RAT malware used for crypto theft, reconnaissance

ID: 977dea08-2e71-5988-97b8-7f13e7502ecb

STIX ID: report--977dea08-2e71-5988-97b8-7f13e7502ecb

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-03-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft reported discovery of StilachiRAT, a sophisticated remote access trojan that evades detection, maintains persistence via Windows services and watchdog threads, steals browser credentials and data from ~20 cryptocurrency wallet extensions, monitors clipboard activity, enumerates and impersonates RDP sessions for lateral movement, and includes anti-analysis and anti-forensics capabilities; Microsoft published IOCs and mitigation guidance but observed limited deployments and has not attributed the tool to a specific actor or region.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.