A newly discovered remote access trojan (RAT) is compromising digital wallet extensions in Google Chrome, posing a serious risk to users’ funds and sensitive data.
Microsoft’s security team detailed the malware, named StilachiRAT, in a March 17 report. First identified in late 2023, the trojan is designed to infiltrate devices and extract credentials, private keys, and other financial information. It specifically targets 20 browser-based wallet extensions, including Coinbase Wallet, MetaMask, Trust Wallet, and OKX, with the goal of stealing user funds.
The malware operates by exploiting a browser module, WWStartupCtrl64.dll, to gain unauthorized access to login data and clipboard activity. It can retrieve stored credentials from Chrome’s local state file and extract passwords or crypto keys copied to the clipboard. To evade detection, StilachiRAT employs anti-forensics techniques, such as clearing event logs and identifying sandbox environments used for security analysis.
Although the origins of the malware remain unknown, Microsoft warns that its ability to adapt and avoid detection makes it a growing concern.
“Based on Microsoft’s current visibility, the malware does not exhibit widespread distribution at this time,”
the company said. However, Microsoft emphasized that publicly sharing details about the threat could help mitigate its spread.
With cyberattacks targeting digital assets on the rise, Microsoft advises users to enhance security measures by using antivirus software, anti-phishing tools, and strong authentication methods to protect their wallets from potential breaches.
Disclaimer: This content does not constitute trading or investment recommendations. It’s essential to conduct your own research before purchasing any cryptocurrency or investing in any services.















