Infosecurity-Magazine SilabRAT Trojan Targets Cryptocurrency with Session Hijacking Techniques
Article Content
- •SilabRAT is a new RAT sold as a MaaS for $5,000 per month, focusing on cryptocurrency theft.
- •It employs advanced techniques like session hijacking and browser-profile cloning to bypass security measures.
- •Over 90% of infected machines reportedly stayed online during campaigns, indicating high operational effectiveness.
The SilabRAT, a Remote Access Trojan (RAT), has emerged on dark web forums as a Malware-as-a-Service (MaaS) offering since late 2025, priced at $5,000 per month. Developed by the Russian-speaking actor 'o1oo1', it is designed to hijack victims' logged-in sessions to steal cryptocurrency, bypassing passwords and multi-factor authentication. The malware employs a hidden virtual network computing (HVNC) solution and browser-profile cloning to maintain control over the victim's session. It has been reported that over 90% of infected machines remained online during a month-long campaign. SilabRAT is often distributed through email spam and ClickFix lures, with antivirus tools misclassifying it as HijackLoader. The developer also offers a code-obfuscation tool called AsmCrypt, which is sold alongside SilabRAT. Group-IB analysts have observed its real-world deployment and expect its focus on cryptocurrency theft to intensify. Security experts recommend enforcing multi-factor authentication and keeping systems updated to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BlackMatter, ClickFix and RAMP in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts Rapid7's Q2 2026 Threat Landscape Report reveals a significant increase in vulnerability disclosures, with high and critical vulnerabilities doubling to 8,539. Newly exploited vulnerabilities surged by 40%, with 62% requiring no user interaction to exploit. The report highlights that attackers are leveraging…
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…