Microsoft has discovered a new Remote Access Trojan (RAT) named StilachiRAT, which employs sophisticated techniques to evade detection and persist in a target environment.
StilachiRAT can steal sensitive data, target cryptocurrency wallets, and perform remote command execution, granting attackers control over infected devices.
The malware maintains persistence through the Windows service control manager, utilizing watchdog threats to recreate itself if removed.
StilachiRAT employs evasion techniques such as clearing event logs and checking for sandbox environments, making analysis more difficult.