digital wallets

Tech Optimizer
March 20, 2025
Microsoft Incident Response has identified a new remote access trojan (RAT) called StilachiRAT, which extracts sensitive information from infected computers, including passwords, cryptocurrency wallet details, operating system specifications, and device identifiers. StilachiRAT has a self-reinstatement mechanism that allows it to reinstall itself if removed. It targets digital wallets from platforms like Coinbase Wallet, Phantom, Trust Wallet, Metamask, OKX Wallet, and Bitget Wallet. The malware can harvest credentials from web browsers, monitor clipboard data, gather system information, detect camera presence, and track active Remote Desktop Protocol (RDP) sessions. It can extract credentials from Google Chrome, monitor clipboard activity, and maintain its presence using the Windows service control manager. StilachiRAT can impersonate users to monitor RDP sessions and employs anti-forensics mechanisms to evade detection. Discovered in November of the previous year, it has not yet achieved widespread distribution. Microsoft advises users to download software from official websites, use robust security software, install reputable antivirus, be vigilant against phishing attacks, avoid clicking on unexpected links, and consider using a VPN and password manager for enhanced security.
Winsage
March 18, 2025
Microsoft has issued a warning to Chrome users about a new remote access trojan called StilachiRAT, which can exfiltrate sensitive information such as stored credentials and digital wallet data. StilachiRAT can scan for configuration data across 20 cryptocurrency wallet extensions in Chrome and can extract and decrypt saved usernames and passwords. The malware can also monitor Remote Desktop Protocol (RDP) sessions, capture active window information, and impersonate users to gain unauthorized access to networks. Microsoft recommends that users switch to its Edge browser or other browsers with SmartScreen technology to enhance security. Additionally, users are advised to install software from official sources, utilize Safe Links and Safe Attachments in Office 365, and enable network protection features in Microsoft Defender for Endpoint. Despite this, Chrome remains the dominant browser among Windows users.
Tech Optimizer
February 28, 2025
As of 2025, there is an increase in malware threats targeting Apple laptops, particularly a revamped version of XCSSET, which can infiltrate Xcode projects and has enhanced capabilities that make it harder to detect. This malware employs advanced code scrambling techniques and disguises its true purpose by renaming code components. Once it infects a Mac, it embeds itself in system files and replaces the Launchpad shortcut with a counterfeit version that runs both the genuine Launchpad and the malware. XCSSET is capable of stealing sensitive information, including data from digital wallets and the Notes app, as well as gathering system information and files. It can be updated with new capabilities, increasing its data-stealing potential over time. To protect against such threats, users are advised to install strong antivirus software, be cautious with downloads and links, keep software updated, use strong and unique passwords, and enable two-factor authentication.
AppWizard
July 16, 2024
Google is working on a feature for Google Wallet that allows users to scan and store text-based documents like student IDs, passports, and resident cards. Private documents need user authentication and will not be stored on Google's system, only locally on the device.
AppWizard
June 26, 2024
2C2P and MineSec have partnered to introduce a cloud-based POS payment app in Singapore that allows businesses to accept contactless payments on their Android devices. The app supports tap-to-pay card payments and QR payments, catering to the growing demand for digital payments in the country. The partnership aims to revolutionize traditional POS systems and may potentially expand into other Asian markets in the future.
AppWizard
June 26, 2024
2C2P and MineSec have launched a cloud-based POS payment app for Android devices in Singapore. The app allows businesses to accept Tap-to-Pay and QR payments directly on NFC-enabled Android devices. It supports major card schemes and popular digital wallets. The collaboration sets the stage for potential expansion into other markets in Asia. The app aims to meet the growing demand for seamless and secure in-store payment solutions.
Search