logo

StilachiRAT analysis: From system reconnaissance to cryptocurrency theft

ID: 2fb77c28-5c99-5cf2-9a9f-220144e31d00

STIX ID: report--2fb77c28-5c99-5cf2-9a9f-220144e31d00

Feed Name: Microsoft Security

Threat Score
70/100

Date Published: 2025-03-17

Date Updated: 2026-04-28

Author: Microsoft Incident Response

...
...

StilachiRAT is a sophisticated remote access trojan documented by Microsoft Incident Response that collects system reconnaissance data, steals Chrome-saved credentials and numerous Chrome extension cryptocurrency wallet configurations, monitors clipboard and RDP sessions, and implements robust persistence and anti-forensic techniques; the report provides technical analysis, C2 indicators (app.95560.cc and 194.195.89.47), a SHA-256 for WWStartupCtrl64.dll, detection/hunting queries, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.