Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Tufts University student Rumeysa Ozturk ordered released from ICE detention | Donald Trump News

May 9, 2025

Tufts University student Rumeysa Ozturk ordered released from ICE detention | Donald Trump News

May 9, 2025

SoundCloud changes policies to allow AI training on user content

May 9, 2025
Facebook X (Twitter) Instagram
Trending
  • Tufts University student Rumeysa Ozturk ordered released from ICE detention | Donald Trump News
  • Tufts University student Rumeysa Ozturk ordered released from ICE detention | Donald Trump News
  • SoundCloud changes policies to allow AI training on user content
  • DeepSeek: Everything you need to know about the AI chatbot app
  • ‘I will run right over you’: New FEMA head issues warning to Trump critics | Donald Trump News
  • In Other News: India-Pakistan Cyberattacks, Radware Vulnerabilities, xAI Leak
  • Popular Scraping Tool’s NPM Package Compromised in Supply Chain Attack
  • UK FinTech lender Juice raises £25m to back SME founders with non-dilutive capital
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Friday, May 9
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Microsoft Warns of New StilachiRAT Malware
Cybersecurity

Microsoft Warns of New StilachiRAT Malware

adminBy adminMarch 19, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 30


Microsoft this week shared details on StilachiRAT, an evasive and persistent piece of malware that enables cybercriminals to steal sensitive data from compromised systems.

The tech giant’s incident response team first spotted StilachiRAT (the name was given by Microsoft) in November 2024. While it currently does not appear to be widely distributed, the company wanted to warn users and organizations.

Microsoft has yet to link StilachiRAT, which has been described as a remote access trojan (RAT), to any known threat group or a specific country.

The company has not specified how the RAT is being distributed, but noted that such threats can be installed through multiple attack vectors, including trojanized software, malicious websites, and email. 

Once it has been deployed on a device, the malware collects information about the system to enable a detailed profiling. StilachiRAT then scans the system for configuration data associated with 20 different cryptocurrency wallet Chrome extensions. 

The RAT extracts usernames and passwords stored in Chrome and continuously monitors clipboard content for valuable information such as credentials and cryptocurrency keys.

The malware can also monitor RDP sessions, which could allow the attacker to move laterally within the compromised network. 

According to Microsoft, StilachiRAT can execute various commands, including to reboot the system, clear logs, manipulate registry entries, and execute applications. 

Advertisement. Scroll to continue reading.

For persistence the malware uses the Windows service control manager and watchdog threads to ensure that it’s restored in case of removal. 

The RAT also packs anti-forensic and evasion capabilities. 

“StilachiRAT displays anti-forensic behavior by clearing event logs and checking certain system conditions to evade detection. This includes looping checks for analysis tools and sandbox timers that prevent its full activation in virtual environments commonly used for malware analysis,” Microsoft explained.

“Additionally, Windows API calls are obfuscated in multiple ways and a custom algorithm is used to encode many text strings and values. This significantly slows down analysis time since extrapolating higher level logic and code design becomes a more complex effort,” it added. “The malware employs API-level obfuscation techniques to impede manual analysis, specifically by concealing its use of Windows APIs.”

Related: 11 State-Sponsored APTs Exploiting LNK Files for Espionage, Data Theft

Related: ClickFix Widely Adopted by Cybercriminals, APT Groups

Related: DeepSeek’s Malware-Generation Capabilities Put to Test



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

In Other News: India-Pakistan Cyberattacks, Radware Vulnerabilities, xAI Leak

May 9, 2025

Popular Scraping Tool’s NPM Package Compromised in Supply Chain Attack

May 9, 2025

160,000 Impacted by Valsoft Data Breach

May 9, 2025

Malicious NPM Packages Target Cursor AI’s macOS Users

May 9, 2025

Rising Tides: Kelley Misata on Bringing Cybersecurity to Nonprofits

May 9, 2025

SAP Zero-Day Targeted Since January, Many Sectors Impacted 

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

Skechers’ Greenbergs Set To Pocket Up To $1.1 Billion From Sale To 3G

May 6, 2025

Skechers founders Robert Greenberg (left) and Michael Greenberg (right) started the brand more than 30…

Trump Organization Admits President Still Controls His Business

May 6, 2025

Forbes Richest Person In Every State 2025

April 30, 2025

These Billionaire Signers Of The Giving Pledge Signers On Why The Philanthropy Group Still Matters

April 29, 2025
Our Picks

Tufts University student Rumeysa Ozturk ordered released from ICE detention | Donald Trump News

May 9, 2025

Tufts University student Rumeysa Ozturk ordered released from ICE detention | Donald Trump News

May 9, 2025

SoundCloud changes policies to allow AI training on user content

May 9, 2025

DeepSeek: Everything you need to know about the AI chatbot app

May 9, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

SoundCloud changes policies to allow AI training on user content

May 9, 2025

DeepSeek: Everything you need to know about the AI chatbot app

May 9, 2025

This is your last chance to exhibit at TechCrunch Sessions: AI — don’t miss out

May 9, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.