StilachiRAT is a newly identified remote access trojan (RAT). Available supporting content describes it as a stealthy RAT targeting credentials and cryptocurrency wallets. It has been referenced by Microsoft and in a Tanium CTI roundup. No additional high-confidence details on infection vector, technical behavior, associated threat actors, targeted industries, platforms, or indicators of compromise are provided in the supplied content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stealthy remote access trojan with persistence and data theft capabilities, including credential and crypto wallet data theft.
StilachiRAT is a remote access trojan (RAT) that provides attackers with persistent access to compromised systems, enabling them to control infected machines remotely.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.