Microsoft: New RAT malware used for crypto theft, reconnaissance
ID: 977dea08-2e71-5988-97b8-7f13e7502ecb
STIX ID: report--977dea08-2e71-5988-97b8-7f13e7502ecb
Feed Name: Bleeping Computer
Microsoft reported discovery of StilachiRAT, a sophisticated remote access trojan that evades detection, maintains persistence via Windows services and watchdog threads, steals browser credentials and data from ~20 cryptocurrency wallet extensions, monitors clipboard activity, enumerates and impersonates RDP sessions for lateral movement, and includes anti-analysis and anti-forensics capabilities; Microsoft published IOCs and mitigation guidance but observed limited deployments and has not attributed the tool to a specific actor or region.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
