Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Women in Mexico find safety in a feminist rideshare network

November 8, 2025

More Pakistani women are joining the country’s firefighters

November 7, 2025

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025
Facebook X (Twitter) Instagram
Trending
  • Women in Mexico find safety in a feminist rideshare network
  • More Pakistani women are joining the country’s firefighters
  • Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why
  • Here’s what to know about a study that raises questions about melatonin use and heart health
  • Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime
  • A Startup Was Their First-Ever Job—Now They’re The World’s Youngest Self Made Billionaires
  • Meet The Former Journalist Giving Away Billions
  • Supermarket Billionaire Reacts To Mamdani’s Win
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Saturday, November 8
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Microsoft Warns of New StilachiRAT Malware
Cybersecurity

Microsoft Warns of New StilachiRAT Malware

By adminMarch 19, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 111


Microsoft this week shared details on StilachiRAT, an evasive and persistent piece of malware that enables cybercriminals to steal sensitive data from compromised systems.

The tech giant’s incident response team first spotted StilachiRAT (the name was given by Microsoft) in November 2024. While it currently does not appear to be widely distributed, the company wanted to warn users and organizations.

Microsoft has yet to link StilachiRAT, which has been described as a remote access trojan (RAT), to any known threat group or a specific country.

The company has not specified how the RAT is being distributed, but noted that such threats can be installed through multiple attack vectors, including trojanized software, malicious websites, and email. 

Once it has been deployed on a device, the malware collects information about the system to enable a detailed profiling. StilachiRAT then scans the system for configuration data associated with 20 different cryptocurrency wallet Chrome extensions. 

The RAT extracts usernames and passwords stored in Chrome and continuously monitors clipboard content for valuable information such as credentials and cryptocurrency keys.

The malware can also monitor RDP sessions, which could allow the attacker to move laterally within the compromised network. 

According to Microsoft, StilachiRAT can execute various commands, including to reboot the system, clear logs, manipulate registry entries, and execute applications. 

Advertisement. Scroll to continue reading.

For persistence the malware uses the Windows service control manager and watchdog threads to ensure that it’s restored in case of removal. 

The RAT also packs anti-forensic and evasion capabilities. 

“StilachiRAT displays anti-forensic behavior by clearing event logs and checking certain system conditions to evade detection. This includes looping checks for analysis tools and sandbox timers that prevent its full activation in virtual environments commonly used for malware analysis,” Microsoft explained.

“Additionally, Windows API calls are obfuscated in multiple ways and a custom algorithm is used to encode many text strings and values. This significantly slows down analysis time since extrapolating higher level logic and code design becomes a more complex effort,” it added. “The malware employs API-level obfuscation techniques to impede manual analysis, specifically by concealing its use of Windows APIs.”

Related: 11 State-Sponsored APTs Exploiting LNK Files for Espionage, Data Theft

Related: ClickFix Widely Adopted by Cybercriminals, APT Groups

Related: DeepSeek’s Malware-Generation Capabilities Put to Test



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply

Don't Miss
Billionaires

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

ToplineTesla shares declined more than 3% on Friday, cutting CEO Elon Musk’s fortune by $10…

Trump’s Bungled Bet On Bitcoin Is Costing Him Bigtime

November 7, 2025

A Startup Was Their First-Ever Job—Now They’re The World’s Youngest Self Made Billionaires

November 7, 2025

Meet The Former Journalist Giving Away Billions

November 7, 2025
Our Picks

Women in Mexico find safety in a feminist rideshare network

November 8, 2025

More Pakistani women are joining the country’s firefighters

November 7, 2025

Musk’s Net Worth Drops $10 Billion—And Tesla Shares Fall—Here’s Why

November 7, 2025

Here’s what to know about a study that raises questions about melatonin use and heart health

November 7, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.