SilabRAT Trojan Targets Cryptocurrency with Session Hijacking Techniques

SilabRAT Trojan Targets Cryptocurrency with Session Hijacking Techniques

First seen 10 Jun 2026, 16:34 UTC Group-Ibsecurelist.comInfosecurity-Magazine 89% similarity 69.5

Article Content

Browse articles
ThreatCluster

The SilabRAT, a Remote Access Trojan (RAT), has emerged on dark web forums as a Malware-as-a-Service (MaaS) offering since late 2025, priced at $5,000 per month. Developed by the Russian-speaking actor 'o1oo1', it is designed to hijack victims' logged-in sessions to steal cryptocurrency, bypassing passwords and multi-factor authentication. The malware employs a hidden virtual network computing (HVNC) solution and browser-profile cloning to maintain control over the victim's session. It has been reported that over 90% of infected machines remained online during a month-long campaign. SilabRAT is often distributed through email spam and ClickFix lures, with antivirus tools misclassifying it as HijackLoader. The developer also offers a code-obfuscation tool called AsmCrypt, which is sold alongside SilabRAT. Group-IB analysts have observed its real-world deployment and expect its focus on cryptocurrency theft to intensify. Security experts recommend enforcing multi-factor authentication and keeping systems updated to mitigate risks.

Key Points: • SilabRAT is a new RAT sold as a MaaS for $5,000 per month, focusing on cryptocurrency theft. • It employs advanced techniques like session hijacking and browser-profile cloning to bypass security measures. • Over 90% of infected machines reportedly stayed online during campaigns, indicating high operational effectiveness.

ThreatCluster AI

Timeline

2025-09-01
SilabRAT first advertised on dark web
SilabRAT began appearing on Russian-language cybercriminal forums as a MaaS offering.
Group-Ib
2025-12-01
SilabRAT real-world deployment observed
Group-IB analysts noted the use of SilabRAT in email spam and ClickFix campaigns.
Group-Ib
2026-01-05
RAMP ransomware forum taken down
The FBI dismantled the RAMP forum, which had previously advertised SilabRAT.
Group-Ib
2026-06-10
Infosecurity Magazine reports on SilabRAT
Infosecurity Magazine published an analysis detailing SilabRAT's capabilities and attack methods.
Infosecurity-Magazine

Community

Browse all →