Microsoft Warns of New Trojan Targeting Crypto in 20 Chrome Wallet Extensions

Microsoft Scam
First detected in November 2023, StilachiRAT operates by extracting credentials stored in browsers.
Author
Author
Ruholamin HaqshanasVerified
Part of the Team Since
Oct 2021
About Author

Ruholamin Haqshanas is a contributing crypto writer for CryptoNews. He is a crypto and finance journalist with over four years of experience. Ruholamin has been featured in several high-profile crypto...

Last updated: 

Microsoft has identified a new cybersecurity threat targeting cryptocurrency users, uncovering a remote access trojan (RAT) that infiltrates digital wallet extensions in Google Chrome.

The tech giant’s Incident Response Team revealed in a March 17 report that the malware, dubbed StilachiRAT, is designed to steal sensitive information from cryptocurrency holders.

First detected in November 2023, StilachiRAT operates by extracting credentials stored in browsers, accessing crypto wallet data, and monitoring clipboard activity.

New Malware Targets 20 Crypto Wallet Extensions to Steal User Funds

Once installed on a device, the malware scans for the presence of 20 targeted wallet extensions, including Coinbase Wallet, Trust Wallet, MetaMask, and OKX Wallet, to siphon user funds.

Microsoft’s analysis found that the trojan exploits WWStartupCtrl64.dll, a module that facilitates various stealthy data theft techniques.

StilachiRAT can retrieve login credentials saved in the Google Chrome local state file and intercept sensitive details, such as passwords and crypto keys, from clipboard activity.

It also employs anti-forensics mechanisms to evade detection by clearing event logs and detecting sandbox environments, which helps cybercriminals bypass security monitoring.

Despite its advanced capabilities, Microsoft has yet to identify the actors behind the malware.

However, the company stressed that publicly sharing its findings could help mitigate its impact.

Microsoft noted that while StilachiRAT has not yet spread on a large scale, its ability to evade detection and rapidly evolve makes it a significant concern.

“Based on Microsoft’s current visibility, the malware does not exhibit widespread distribution at this time,” the company said.

“However, due to its stealth capabilities and the rapid changes within the malware ecosystem, we are sharing these findings as part of our ongoing efforts to monitor, analyze, and report on the evolving threat landscape.”

Crypto Cyberattacks Surge as Hackers Deploy Sophisticated Tactics

The discovery comes amid a surge in crypto-related cyberattacks, with hackers increasingly targeting digital assets through sophisticated methods.

Microsoft advised crypto users to strengthen their security measures by implementing antivirus software, cloud-based anti-phishing tools, and strong anti-malware protections to minimize risk.

The rise in malware attacks on cryptocurrency holders coincides with an alarming spike in crypto-related fraud.

Blockchain security firm CertiK reported that crypto scams, hacks, and exploits led to $1.53 billion in losses in February, with the $1.4 billion Bybit hack accounting for the bulk of the damage.

Meanwhile, Chainalysis’ 2025 Crypto Crime Report highlighted how crypto crime is evolving into a highly professionalized industry, driven by AI-powered scams, stablecoin laundering, and sophisticated cyber syndicates, with illicit transaction volumes surpassing $51 billion last year.

In February 2025, losses in the crypto ecosystem increased by 20x month-over-month compared with January 2025, according to the latest report by major blockchain security platform Immunefi.

In January, registered losses stood at $73,915,700. Just a month later, this figure jumped to $1,528,342,400. The latter was the result of nine hacks.

Additionally, the February number is an 18x increase from the same time a year prior. In February 2024, registered losses were $81,603,400.

In the Article
Bitcoin
BTC
$88,113
0.32 %
Ethereum
ETH
$2,977
0.23 %
XRP
XRP
$1.9267
0.60 %
Litecoin
LTC
$77.21
0.45 %
Cardano
ADA
$0.3691
1.24 %

2M+

Active Monthly Users Around the World

250+

Guides and Reviews Articles

8

Years on the Market

70

International Team Authors
editors
+72 More
At Cryptonews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2017, Cryptonews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.

Best Crypto ICOs

Discover trending tokens still in presale — early-stage picks with potential.

Explore Our Tools

Smart tools made for everyday crypto users

Market Overview

  • 7d
  • 1m
  • 1y
Market Cap
$3,118,184,377,144
-1.19
Trending Crypto

More Articles

Price Analysis
XRP Price Prediction: Binance On-Chain Chart Flags Further XRP Downside — Is $1.50 the Next Support?
Anas Hassan
Anas Hassan
2025-12-20 19:08:41
Price Analysis
Bitcoin Price Prediction: Fundstrat Tells Clients to Brace for a $60K Bitcoin Correction Next Year
Anas Hassan
Anas Hassan
2025-12-20 14:13:47
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors