Infosecurity-Magazine
SilabRAT Trojan Targets Cryptocurrency with Session Hijacking Techniques
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The SilabRAT, a Remote Access Trojan (RAT), has emerged on dark web forums as a Malware-as-a-Service (MaaS) offering since late 2025, priced at $5,000 per month. Developed by the Russian-speaking actor 'o1oo1', it is designed to hijack victims' logged-in sessions to steal cryptocurrency, bypassing passwords and multi-factor authentication. The malware employs a hidden virtual network computing (HVNC) solution and browser-profile cloning to maintain control over the victim's session. It has been reported that over 90% of infected machines remained online during a month-long campaign. SilabRAT is often distributed through email spam and ClickFix lures, with antivirus tools misclassifying it as HijackLoader. The developer also offers a code-obfuscation tool called AsmCrypt, which is sold alongside SilabRAT. Group-IB analysts have observed its real-world deployment and expect its focus on cryptocurrency theft to intensify. Security experts recommend enforcing multi-factor authentication and keeping systems updated to mitigate risks.
Key Points: • SilabRAT is a new RAT sold as a MaaS for $5,000 per month, focusing on cryptocurrency theft. • It employs advanced techniques like session hijacking and browser-profile cloning to bypass security measures. • Over 90% of infected machines reportedly stayed online during campaigns, indicating high operational effectiveness.