trojan targets chrome crypto wallets

While cryptocurrency owners focus on market volatility, a far more immediate threat lurks in their browsers. Microsoft researchers recently discovered StilachiRAT, a sophisticated remote access trojan that specifically targets Google Chrome‘s cryptocurrency wallet extensions. First identified in November 2024, this malware has already developed capabilities to compromise 20 popular crypto wallets including Coinbase Wallet, MetaMask, Trust Wallet, and OKX Wallet.

This isn’t your average virus. StilachiRAT employs advanced anti-forensic techniques to hide from detection, clearing event logs and evading sandbox environments that security researchers use to analyze threats. It’s like having a burglar who not only breaks in but erases the security camera footage on the way out.

Once installed, the trojan gets busy. It monitors clipboard activity (yes, those copy-pasted passwords), collects system information, and scans for wallet extensions to extract credentials. The full extent of this vulnerability became public when Microsoft published detailed findings on March 17, 2025. The malware even watches for active Remote Desktop sessions to impersonate users. Your digital signature becomes its disguise.

The trojan maintains persistence by modifying Windows service settings and communicates with command servers through randomly selected TCP ports. Translation: it’s hard to remove and constantly phones home to its creators.

While not yet widely distributed, StilachiRAT represents the evolving sophistication of cryptocurrency crime. With nearly $1.53 billion lost to crypto crimes in February alone and approximately $51 billion in illicit transactions last year, the stakes couldn’t be higher.

Protect yourself immediately. Download software exclusively from official sources. Update Microsoft Defender, which can now detect StilachiRAT activity. Enable Safe Links and Safe Attachments if you use Microsoft 365. Activate network protection in Microsoft Defender for Endpoint. Consider transferring your assets to hardware wallets for maximum protection against browser-based threats like StilachiRAT.

You May Also Like

Ethereum-Targeted Crypto Hacks Drain $2.37B in Just 121 Attacks: Fewer Incidents, Bigger Losses

Ethereum hacks drain $2.37B in just 121 attacks—fewer incidents but 2.3x bigger losses. Even cold wallets aren’t safe anymore. Your crypto might be next.

Mozilla’s Firefox Hit by Surge of Fake Crypto Wallet Extensions Stealing Users’ Funds

Firefox users beware: Over 40 fake crypto wallet extensions are draining accounts while flaunting perfect 5-star reviews. Thieves have perfected their heist, leaving victims with zero chance of recovery.

Microsoft Warns of Stealthy Malware Draining Coinbase and MetaMask Wallets

Is your cryptocurrency truly yours? Microsoft exposes StilachiRAT malware silently emptying Coinbase and MetaMask wallets while you browse. Your digital fortune might be vanishing right now.

Are AI Bots Coming for Your Crypto? The Rise of Relentless Digital Thieves

AI bots are siphoning billions in crypto through evolved scams while your digital wallet remains vulnerable. One person can deploy thousands of relentless thieves simultaneously. Your security depends on knowing their tactics.