Odaily Planet Daily News Technology giant Microsoft has discovered a new remote access Trojan (RAT) that specifically targets 20 cryptocurrency wallet extensions in Google Chrome browsers to steal crypto assets. Microsoft first detected this malware called StilachiRAT in November last year. The software is capable of stealing credentials, digital wallet information, and clipboard data stored in the browser. After deployment, attackers can use StilachiRAT to scan the configuration information of 20 cryptocurrency wallet extensions to steal encrypted wallet data, including Coinbase Wallet, Trust Wallet, MetaMask, and OKX Wallet.
Microsoft analysis pointed out: "Research on the WWStartupCtrl64.dll module of StilachiRAT, which contains RAT functions, shows that it uses multiple means to steal information from the target system." Among other functions, the malware can also extract credentials saved in Google Chrome's local state files and monitor clipboard activity to obtain sensitive information such as passwords and encryption keys. It also has detection evasion and anti-forensics features, such as clearing event logs and checking if it is running in a sandbox to prevent analysis attempts.
At present, Microsoft has not been able to determine who is behind the malware, but hopes to reduce the number of potential victims by sharing information publicly. Microsoft recommends that users take measures to avoid becoming victims of malware, including installing antivirus software, cloud-based anti-phishing and anti-malware components on their devices. (Cointelegraph)