Newer Millenium RAT versions have been associated with cryptocurrency and browser-extension wallet data theft in public reporting. This expands the malware's impact beyond credentials and cookies into high-value financial assets.
The defensive implication is significant. If cryptocurrency-wallet secrets, seed phrases, private keys, or authenticated browser sessions were accessible from the compromised computer, assume those secrets may have been exposed and follow the appropriate wallet/account migration procedures from a clean environment.
Unlike passwords, cryptocurrency wallet seed phrases cannot simply be "rotated." Migration means creating a new wallet from a clean, trusted device and transferring funds, then treating the old wallet and its secrets as compromised. This is why incident response for Millenium RAT is broader than deleting a single file — the exposure of secrets can outlive the malware itself.

