It performs extensive system reconnaissance, collecting details such as operating system information, BIOS (Basic Input/Output System) serial numbers, camera presence and active remote desktop protocol (RDP) sessions. With a focus on stealing cryptocurrencies, StilachiRAT scans for up to 20 crypto wallet extensions within Chrome, including those from Coinbase, Fractal, Phantom, Manta and Bitget.
Extracted credentials originate from the following locations: %LOCALAPPDATA%GoogleChromeUser DataLocal State, which holds Chrome’s configuration data, inclusive of the encrypted key %LOCALAPPDATA%GoogleChromeUser DataDefaultLogin Data, which preserves user credentials input into Chrome. The “Login Data” file constitutes an SQLite database, and the malware extracts credentials using a defined database query.
Brute-force RDP attacks: Cybercriminals attempt to gain unauthorized access by systematically guessing remote desktop protocol (RDP) credentials, allowing them to install malware remotely.USB droppers: Attackers distribute infected USB drives that automatically install malware when connected to a system.Drive-by downloads: Visiting compromised or malicious websites can result in automatic malware downloads without the user’s knowledge.
More Pictures
or
Share This Story
Article Details
Author / Journalist: Cointelegraph by Dilip Kumar Patairya
The story "StilachiRAT malware: How it targets crypto wallets on Chrome" has 1395 words across 78 sentences, which will take approximately 6 - 12 minutes for the average person to read.
Which news outlet covered this story?
The story "StilachiRAT malware: How it targets crypto wallets on Chrome" was covered 6 days ago by Coin Telegraph, a news publisher based in United States.
How trustworthy is 'Coin Telegraph' news outlet?
Coin Telegraph is a fully independent (privately-owned) news outlet established in 2013 that covers mostly crypto news.
The outlet is headquartered in United States and publishes an average of 9 news stories per day.
It's most recent story was published 9 hours ago.
What do people currently think of this news story?
The sentiment for this story is currently Negative, indicating that people regard this as "bad news".
How do I report this news for inaccuracy?
You can report an inaccurate news publication to us via our contact page. Please also include the news #ID number and the URL to this story.