News View Non-AMP

Trojan Malware Hits Crypto Wallets: What MetaMask, Coinbase and Other Users Need to Know

Published by
Anjali Belgaumkar

Microsoft has issued a warning about a new Trojan malware, StilachiRAT, which targets cryptocurrency wallet extensions on the Google Chrome browser. Discovered by Microsoft’s Incident Response team in November 2024, StilachiRAT is capable of stealing sensitive information, such as stored browser credentials, digital wallet data, clipboard content, and system details.

The malware affects 20 different crypto wallet extensions, including  Bitget Wallet, Trust Wallet, TronLink, MetaMask, TokenPocket, BNB Chain Wallet, OKX Wallet, Sui Wallet, Braavos – Starknet Wallet, Coinbase Wallet, Leap Cosmos Wallet, Manta Wallet, Keplr, Phantom, Compass Wallet for Sei, Math Wallet, Fractal Wallet, Station Wallet, ConfluxPortal, and Plug. While the malware has not yet been widely distributed, it poses a serious threat due to its stealthy methods of operation.

What Users Should Do

If you use crypto wallet extensions on Google Chrome, it’s crucial to be cautious. Microsoft recommends checking your browser plugins, clearing your browser history, and running antivirus scans. Users should also avoid downloading any suspicious files and ensure they are taking the necessary steps to secure their wallets.

How StilachiRAT Works

StilachiRAT uses various techniques to avoid detection and persist within the target system. One of the malware’s components, WWStartupCtrl64.dll, is responsible for gathering sensitive information, such as credentials stored in browsers and crypto wallets, making it a serious threat for anyone using these wallet extensions.

Microsoft has not yet identified the creators or origin of StilachiRAT, but has shared the findings as part of its ongoing efforts to monitor and address emerging cyber threats.

Protection Measures

Microsoft is providing mitigation guidance to help reduce the impact of StilachiRAT. The malware can be delivered through various vectors, so it is important to implement security measures to prevent compromise.

Anjali Belgaumkar

Writer by choice, CryptoCurrency Writer, and Researcher by chance. Currently, focusing on financial news and analysis, as well as cryptocurrency news and data. One may not call me a crypto “Enthusiast” but trust me I'm getting there.

Recent Posts

5 Must-Buy Cryptos for June 2025: Explore Beyond Solana (SOL) With These Super Bullish Picks

Solana has experienced a significant surge in 2025, scaling up to challenge Ethereum’s dominance in…

June 14, 2025

Exploring Solana’s Best Meme Coins and Early Presales Made Simple June 2025

Overview of Solana’s standout meme tokens gaining traction this month Snapshot of SPX6900, TRUMP, FARTCOIN,…

June 14, 2025

Stablecoin Performace in 2025 Jan To June

Stablecoins have cemented their role in the digital finance revolution as one of the stabilizing…

June 14, 2025

From Zero to Moon: Tiny Crypto Projects With Giant Potential

The crypto industry has been on fire in the last few days. It has seen…

June 14, 2025

WazirX Users May Won’t Get Full Lost Funds Back – Here’s Why!

WazirX users who lost their funds in the 2023 hack might soon get some relief,…

June 14, 2025

Crypto Tax India Crackdown: CBDT Sends Notices to Thousands for Undeclared Income

India’s Central Board of Direct Taxes (CBDT) has initiated a large-scale investigation into individuals and…

June 14, 2025