StilachiRAT analysis: From system reconnaissance to cryptocurrency theft
ID: 2fb77c28-5c99-5cf2-9a9f-220144e31d00
STIX ID: report--2fb77c28-5c99-5cf2-9a9f-220144e31d00
Feed Name: Microsoft Security
StilachiRAT is a sophisticated remote access trojan documented by Microsoft Incident Response that collects system reconnaissance data, steals Chrome-saved credentials and numerous Chrome extension cryptocurrency wallet configurations, monitors clipboard and RDP sessions, and implements robust persistence and anti-forensic techniques; the report provides technical analysis, C2 indicators (app.95560.cc and 194.195.89.47), a SHA-256 for WWStartupCtrl64.dll, detection/hunting queries, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
