Close Menu
  • Home
  • Articles
  • Cryptocurrency
    • Market Analysis
    • Exchanges
    • Investment
  • Blockchain
    • Financial Market
    • Bank
    • Wallet
    • Payment
    • DeFi
    • Blockchain Platform
    • Supply Chain
    • DApps
  • Technology
    • Bitcoin
    • Ethereum
    • Other Currencies
  • Reports
    • Private Sector Report
    • Rating Report
    • Novice Tutorial
    • Interviews
    • Exclusive View
  • All Posts
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
BlockMediaBlockMedia
Subscribe
  • Home
  • Articles
  • Cryptocurrency
    • Market Analysis
    • Exchanges
    • Investment
  • Blockchain
    • Financial Market
    • Bank
    • Wallet
    • Payment
    • DeFi
    • Blockchain Platform
    • Supply Chain
    • DApps
  • Technology
    • Bitcoin
    • Ethereum
    • Other Currencies
  • Reports
    • Private Sector Report
    • Rating Report
    • Novice Tutorial
    • Interviews
    • Exclusive View
  • All Posts
BlockMediaBlockMedia
Home » Microsoft Issues Warning About New Malicious Trojan Targeting 20 Major Web3 Wallets Including OKX and Metamask
Blockchain

Microsoft Issues Warning About New Malicious Trojan Targeting 20 Major Web3 Wallets Including OKX and Metamask

By adminMar. 18, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Microsoft Issues Warning About New Malicious Trojan Targeting 20 Major Web3 Wallets Including OKX and Metamask
Microsoft Issues Warning About New Malicious Trojan Targeting 20 Major Web3 Wallets Including OKX and Metamask
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email

Microsoft Uncovers StilachiRAT: A New Remote Access Trojan Targeting Cryptocurrency Wallets

In a blog post released by Microsoft’s Incident Response Team yesterday, a new type of remote access Trojan called StilachiRAT was revealed. This malware has multiple data theft capabilities, including the ability to retrieve user credentials stored in browsers, steal cryptocurrency wallet information, monitor and extract clipboard data, and more. It has been discovered to target cryptocurrency wallet extensions within the Chrome browser, affecting up to 20 popular Chrome wallet extensions, including OKX Wallet and MetaMask.

Background: North Korean Hacker Group Lazarus Behind Web3’s Largest Heist

Additional Context: In-Depth Analysis of Bybit’s Biggest Hack Ever, How Can Industry Security Improve?

On March 17, tech giant Microsoft published an announcement revealing a new remote access Trojan named StilachiRAT. This malicious software can target cryptocurrency wallet extensions within the Chrome browser, potentially affecting up to 20 major wallet extensions used by Chrome.

Wallets Affected Include OKX, MetaMask, and More

According to a report posted by Microsoft’s Incident Response Team, StilachiRAT was first discovered in November of last year and is capable of stealing multiple types of data. These include retrieving user credentials saved in browsers, stealing cryptocurrency wallet information, monitoring and extracting clipboard data, and more.

After StilachiRAT is deployed, the Trojan scans the user’s device to check if 20 types of cryptocurrency wallet extensions, such as Coinbase Wallet, Trust Wallet, MetaMask, or OKX Wallet, are installed. Upon finding a target, it initiates the data theft process.

The List of 20 Affected Wallets Includes:

  • Bitget Wallet
  • Trust Wallet
  • TronLink
  • MetaMask (Ethereum)
  • TokenPocket
  • BNB Chain Wallet
  • OKX Wallet
  • Sui Wallet
  • Braavos
  • Coinbase Wallet
  • Leap Cosmos Wallet
  • Manta Wallet
  • Keplr
  • Phantom
  • Compass Wallet
  • Math Wallet
  • Fractal Wallet
  • Station Wallet
  • ConfluxPortal
  • Plug

In addition to directly stealing wallet information, StilachiRAT can also:

  • Extract saved credentials from Google Chrome’s local state files
  • Monitor clipboard activity
  • Intercept sensitive information such as passwords and cryptographic keys
  • Use anti-detection techniques such as clearing event logs and detecting sandbox environments to avoid security analysis

Currently, StilachiRAT Has Not Spread Widely

Additionally, Microsoft has stated that the identity of the developers behind this malicious software is still unknown. However, based on existing monitoring data, StilachiRAT has not spread on a large scale. Nevertheless, due to the Trojan’s stealthy nature and the rapidly evolving landscape of malicious software, the Microsoft team decided to publicly share this information:

“Given StilachiRAT’s high degree of stealth and the rapidly changing nature of the malware ecosystem, we have decided to publicly share these findings as part of our ongoing effort to monitor, analyze, and report on the evolving threat landscape.”

Security Recommendations from Microsoft:

  • Install and keep antivirus software updated
  • Enable cloud-based anti-phishing and anti-malware protection
  • Regularly check the security status of your devices

In the dark corners of the cryptocurrency world, cases of user accounts being hacked are frequent. We remind readers not to grant wallet permissions casually, avoid clicking on suspicious links, and regularly check their computer security. Always stay security-conscious when interacting with wallets.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicroStrategy Reinitiates “Buy, Buy, Buy” Strategy? A Comprehensive Analysis of the New Financing Plan
Next Article Binance: Full Compensation for BNB Chain Margin Losses During Limited Time, Zero Fees on Binance Wallet for Six Months

Related Posts

Federal Bank Explains the Ban on Scheduled Transfers: High Proportion of Alert Accounts in Cryptocurrency Accounts Makes Fraudulent Money Flows Difficult to Track.

Jun. 18, 2025

ARK Invest Sells Approximately $51.7 Million of Circle Stock, Representing Only 10% of Cost Basis

Jun. 17, 2025

Is the Only Path for Altcoins to Enter the Mainstream? DWF Labs Optimistic About Nasdaq Listing Potential

Jun. 13, 2025
Don't Miss

Federal Bank Explains the Ban on Scheduled Transfers: High Proportion of Alert Accounts in Cryptocurrency Accounts Makes Fraudulent Money Flows Difficult to Track.

By adminJun. 18, 2025

Taiwan’s Two Major Financial Institutions Suspend Virtual Currency Platform Account TransfersRecentl…

Understanding Ethereum ERC-7786: A Unified Multichain Collaboration Standard, Heralding the Era of “Unity” in the ETH Ecosystem?

Jun. 18, 2025

ARK Invest Sells Approximately $51.7 Million of Circle Stock, Representing Only 10% of Cost Basis

Jun. 17, 2025

What Could Be the Potential Peak of Bitcoin This Cycle? An Analysis Using Multiple Valuation Models

Jun. 17, 2025
Our Picks

Federal Bank Explains the Ban on Scheduled Transfers: High Proportion of Alert Accounts in Cryptocurrency Accounts Makes Fraudulent Money Flows Difficult to Track.

Jun. 18, 2025

Understanding Ethereum ERC-7786: A Unified Multichain Collaboration Standard, Heralding the Era of “Unity” in the ETH Ecosystem?

Jun. 18, 2025

ARK Invest Sells Approximately $51.7 Million of Circle Stock, Representing Only 10% of Cost Basis

Jun. 17, 2025

What Could Be the Potential Peak of Bitcoin This Cycle? An Analysis Using Multiple Valuation Models

Jun. 17, 2025
Latest Posts

Federal Bank Explains the Ban on Scheduled Transfers: High Proportion of Alert Accounts in Cryptocurrency Accounts Makes Fraudulent Money Flows Difficult to Track.

Jun. 18, 2025

Understanding Ethereum ERC-7786: A Unified Multichain Collaboration Standard, Heralding the Era of “Unity” in the ETH Ecosystem?

Jun. 18, 2025

ARK Invest Sells Approximately $51.7 Million of Circle Stock, Representing Only 10% of Cost Basis

Jun. 17, 2025

What Could Be the Potential Peak of Bitcoin This Cycle? An Analysis Using Multiple Valuation Models

Jun. 17, 2025
About Us
About Us

BlockMedia, your comprehensive source for breaking blockchain news, in-depth analysis, and valuable resources. Unravel the blockchain revolution as it happens, with us.

Categories
© 2025 blockogmedia .

Type above and press Enter to search. Press Esc to cancel.