Target Industry

Indiscriminate, opportunistic targeting.

Overview

A new remote access trojan (RAT) named StilachiRAT is posing a significant threat. Discovered by Microsoft Incident Response researchers, this malware is designed to evade detection and maintain persistence in the target environment. StilachiRAT is capable of stealing credentials and system information. 

Impact

Users are at serious risk of data theft because StilachiRAT targets sensitive data stored on devices. The stolen data includes credentials from browsers, digital wallet data, clipboard content, and system information. StilachiRAT is designed to search for and collect configuration data from 20 different cryptocurrency wallet extensions specifically used in the Google Chrome browser. This configuration data can include details such as wallet addresses, private keys, and other sensitive information that could be used to access and steal digital assets stored in these wallets.  

 

The wallets affected by the StilachiRAT are: 

  • Bitget Wallet 
  • BNB Chain Wallet 
  • Braavos – Starknet Wallet 
  • Coinbase Wallet 
  • Compass Wallet for Sei 
  • ConfluxPortal 
  • Fractal Wallet 
  • Keplr 
  • Leap Cosmos Wallet 
  • Manta Wallet 
  • Math Wallet 
  • MetaMask 
  • OKX Wallet 
  • Phantom 
  • Plug 
  • Station Wallet 
  • Sui Wallet 
  • TokenPocket 
  • TronLink 
  • Trust Wallet.

Exploitation

Currently, Microsoft has been unable to determine how the malware is delivered, but it can target a system through multiple initial access routes. Once the malware is on a system, it starts to gather details of the operating system, as well as looking for active Remote Desktop Protocol (RDP) sessions, BIOS serial numbers, and any Graphical User Interface (GUI) applications. 

The malware communicates with a command-and-control (C2) server using domain names that are intentionally scrambled or disguised, and instead of using standard IP address formats, the malware encodes IP addresses in a binary format. Additionally, StilachiRAT executes various commands as part of its anti-forensic tactics, including system reboot, log clearing, credential theft, application execution, and registry modifications

Containment, Mitigations & Remediation

To mitigate against StilachiRAT malware, always download software from reputable sources to avoid malicious software posing as legitimate updates. Utilise Microsoft Edge and other browsers with SmartScreen to block malicious websites. Activate Safe Links and Safe Attachments in Microsoft Defender for Office 365 to protect against harmful links and email attachments. Enable network protection in Microsoft Defender for Endpoint to prevent access to malicious domains and content on the internet. 

TCP ports 53, 443, and 16000 should be monitored for unusual outbound connections. Additionally, audit the event logs for the following events: 

  • Event ID 7045: new service installed 
  • Event ID 7040: service settings modified 
  • Event IDs 1102 and 104: event log clearing. 

Threat Landscape

There are roughly 420 million people worldwide who have their own crypto wallet with approximately 833.70 million cryptocurrency users worldwide. Therefore, StilachiRAT poses a significant threat due to its focus on cryptocurrency theft and its ability to evade detection while maintaining persistence on compromised systems.  

Threat Group

The specific threat group behind this has not been publicly identified at the time of writing. 

Tactics, Techniques, and Procedures (TTPs)

  • T1059: Command and Scripting Interpreter 
  • T1047: Windows Management Instrumentation 
  • T1059.001: Command and Scripting Interpreter: PowerShell 
  • T1505.004: Server Software Component: IIS Components 
  • T1631: Process Injection 
  • T1070:  Indicator Removal 
  • T1070.001: Indicator Removal: Clear Windows Event Logs 
  • T1555.003: Credentials from Password Stores: Credentials from Web Browsers 
  • T1082: System Information Discovery 
  • T1021.001: Remote Services: Remote Desktop Protocol 
  • T1071.001: Application Layer Protocol: Web Protocols 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content