Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    MicroStrategy Stock Mirrors Bitcoin's Wildest Swings 7 Times BTC Moved MSTR
    MicroStrategy Stock Mirrors Bitcoin’s Wildest Swings: 7 Times BTC Moved MSTR
    Beyond Bitcoin Treasuries How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    Beyond Bitcoin Treasuries: How Hyperliquid’s Revenue-Backed HYPE Is Creating Self-Funding Corporate Balance Sheets
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    The Unresolved Debate Reignites: Is Bitcoin a Pyramid Scheme?
    Exclusive Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Exclusive: Coinbase Says No Other International Launch For 12 Months, India Is the Bet
    Crypto PACs Reshape US Elections: Trump's Pro-Crypto Agenda Takes Shape
    Crypto PACs Reshape US Elections: Trump’s Pro-Crypto Agenda Takes Shape
  • Opinion
    OpinionShow More
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
    Bitcoin Pizza Day Was Never Really About Pizza
    Bitcoin Pizza Day Was Never Really About Pizza
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Microsoft Discovers StilachiRAT Malware Targeting Crypto Wallets

StilachiRAT silently pulls all this info using Windows Management Instrumentation (WMI) queries.

Written By:
Dishita Malvania

Reviewed By:
Dhara Chavda

Last updated: March 19, 2025 5:40 PM
Published 2025-03-19
Share
Last updated: March 19, 2025 5:40 PM
Published 2025-03-19
Microsoft Discovers StilachiRAT Malware Targeting Crypto Wallets

If you’re into crypto, here’s a fresh security alert you can’t ignore. Microsoft has uncovered a sneaky new malware called StilachiRAT, a remote access trojan (RAT) designed to steal sensitive data—including login credentials, clipboard content, and, most importantly, your crypto wallet info.

Back in November 2024, security researchers stumbled upon StilachiRAT. This malware hides inside a file called WWStartupCtrl64.dll and is packed with sneaky tricks to avoid getting caught. Microsoft hasn’t pinned it on any particular hacker group yet, but one thing is clear: it’s built to steal as much sensitive info as possible.

Here’s what it goes after:

  • Passwords saved in your browser
  • Crypto wallet details (yep, those funds aren’t safe if this thing gets in)
  • Clipboard data, meaning if you copy-paste passwords or wallet addresses, it snatches them
  • System details like BIOS serial numbers, whether your webcam is active, and even any ongoing Remote Desktop (RDP) sessions

And it doesn’t make a scene while doing this. Instead, StilachiRAT silently pulls all this info using Windows Management Instrumentation (WMI) queries. It stays under the radar, so you won’t even know it’s hiding.

Crypto Wallets at Risk

The RAT specifically targets a range of Chrome wallet extensions, including:

  • MetaMask
  • Trust Wallet
  • Coinbase Wallet
  • TronLink
  • OKX Wallet
  • Phantom and many more. 

This isn’t just a passive info-stealer. StilachiRAT is built for more, supporting at least 10 dangerous commands, including:

  • Wiping event logs to cover its tracks
  • Shutting down the system via hidden Windows APIs
  • Killing network connections
  • Running specific applications
  • Searching for certain open windows on the desktop
  • Stealing saved Chrome passwords
  • Forcing the system into sleep or hibernation mode

And to make things worse, it constantly checks if it’s being analyzed, refusing to run properly in security testing environments.

Meanwhile, cybersecurity researchers at Palo Alto Networks’ Unit 42 have flagged three other concerning malware samples:

  • An IIS backdoor that executes hidden commands through HTTP requests.
  • A bootkit that installs a modified GRUB 2 bootloader—one that, weirdly enough, plays Dixie through the PC speaker after rebooting (either a prank or a distraction tactic).
  • A Windows implant of ProjectGeass, a powerful post-exploitation tool built in C++.

StilachiRAT is just another reminder that online threats are always evolving, especially for crypto users. To stay safe, make sure your security software is always up to date, and be extra careful about what you download or click—random links and unknown sources can be risky.

Also Read: Cathie Wood Warns Memecoins Are Likely to Become “Worthless”

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Microsoft
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Dishita Malvania - Senior crypto journalist at The Crypto Times
By Dishita Malvania
Follow:
Dishita Malvania is a Crypto Journalist with 3 years of experience covering the evolving landscape of blockchain, Web3, AI, finance, and B2B tech. With a background in Computer Science and Digital Media, she blends technical knowledge with sharp editorial insight. Dishita reports on key developments in the crypto world—including Litecoin, WazirX, Solana, Cardano, and broader blockchain trends—alongside interviews with notable figures in the space. Her work has been referenced by top digital media outlets like Entrepreneur.com, The Independent, The Verge, and Metro.co, especially on trending topics like Elon Musk, memecoins, Trump, and notable rug pulls.
Dhara Chavda- Crypto Research Analyst at The Crypto Times
By Dhara Chavda
Follow:
Dhara Chavda is a Content Strategist and Research Analyst with 5 years of experience in the crypto industry. She holds a Bachelor’s degree in Computer Engineering and brings a strong technical perspective to her work. Dhara specializes in DeFi, price analysis, and the core mechanics of cryptocurrencies. She also works on crypto news, including research, analysis, and assigning stories, ensuring accurate and timely coverage of key developments in the space.

Latest News

UK FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsors
UK FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsors
Crypto Critic Brad Sherman Advances to November Rematch — Will FairShake Bother Spending
Crypto Critic Brad Sherman Advances to November Rematch — Will FairShake Bother Spending?
MicroStrategy Stock Mirrors Bitcoin's Wildest Swings 7 Times BTC Moved MSTR
MicroStrategy Stock Mirrors Bitcoin’s Wildest Swings: 7 Times BTC Moved MSTR
Tether-Backed Adecoagro to Launch Sugarcane-Powered Bitcoin Mining Hub
Tether-Backed Adecoagro to Launch Sugarcane-Powered Bitcoin Mining Hub
Bitcoin Price Drops Below $66,000 While Massive Selloff Leads $1.86B in Liquidations
Bitcoin Price Drops Below $66,000 While Massive Selloff Leads $1.86B in Liquidations 

Find Us on Socials

You may also like

Crypto Market Today BTC Falls to $67K as $1.23B Liquidations Hit Traders

Crypto Market Today: BTC Falls to $67K as $1.23B Liquidations Hit Traders

Google Co-Author Raises Q-Day Odds as Quantum Breakthroughs Accelerate

Google Co-Author Raises Q-Day Odds as Quantum Breakthroughs Accelerate

RedotPay Launches 'Connect' Gateway to Cut Merchant Fees by 70%

RedotPay Launches ‘Connect’ Gateway to Cut Merchant Fees by 70%

Cardano and Brazilian Olympic Committee Team Up to Boost Sports Tech

Cardano and Brazilian Olympic Committee Team Up to Boost Sports Tech

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information