The malware, StilachiRAT, systematically scans for wallet extensions and passwords, collecting valuable account information. Cybercriminals use this data to steal funds by accessing accounts. It also tracks Operating System details and Remote Desktop Protocol (RDP) sessions enabling attackers to impersonate users for further network infiltration.

Mandiant warns of attacks on newly-disclosed Ivanti remote takeover threat
Google’s Mandiant team has issued an alert about a remote code execution flaw in the Ivanti Connect Secure VPN platform. The vulnerability, designated CVE-2025-22457, is