Skip to content
SilabRAT Trojan Targets Cryptocurrency with Session Hijacking Techniques

SilabRAT Trojan Targets Cryptocurrency with Session Hijacking Techniques

First seen 10 Jun 2026, 16:34 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 11, 2026 at 16:11 UTC
  • SilabRAT is a new RAT sold as a MaaS for $5,000 per month, focusing on cryptocurrency theft.
  • It employs advanced techniques like session hijacking and browser-profile cloning to bypass security measures.
  • Over 90% of infected machines reportedly stayed online during campaigns, indicating high operational effectiveness.

The SilabRAT, a Remote Access Trojan (RAT), has emerged on dark web forums as a Malware-as-a-Service (MaaS) offering since late 2025, priced at $5,000 per month. Developed by the Russian-speaking actor 'o1oo1', it is designed to hijack victims' logged-in sessions to steal cryptocurrency, bypassing passwords and multi-factor authentication. The malware employs a hidden virtual network computing (HVNC) solution and browser-profile cloning to maintain control over the victim's session. It has been reported that over 90% of infected machines remained online during a month-long campaign. SilabRAT is often distributed through email spam and ClickFix lures, with antivirus tools misclassifying it as HijackLoader. The developer also offers a code-obfuscation tool called AsmCrypt, which is sold alongside SilabRAT. Group-IB analysts have observed its real-world deployment and expect its focus on cryptocurrency theft to intensify. Security experts recommend enforcing multi-factor authentication and keeping systems updated to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2025-09-01
SilabRAT first advertised on dark web
SilabRAT began appearing on Russian-language cybercriminal forums as a MaaS offering.
Group-Ib
2025-12-01
SilabRAT real-world deployment observed
Group-IB analysts noted the use of SilabRAT in email spam and ClickFix campaigns.
Group-Ib
2026-01-05
RAMP ransomware forum taken down
The FBI dismantled the RAMP forum, which had previously advertised SilabRAT.
Group-Ib
2026-06-10
Infosecurity Magazine reports on SilabRAT
Infosecurity Magazine published an analysis detailing SilabRAT's capabilities and attack methods.
Infosecurity-Magazine

More articles in this cluster (3)

Following this threat?

Track BlackMatter, ClickFix and RAMP in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed