216.73.217.22

SilabRAT, What's Your Power?

· Published 10/06/2026 13:58 · Modified 10/06/2026 14:01

Export JSON

Essential information

Published
10/06/2026 13:58
Modified
10/06/2026 14:01
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
asmcrypt browser profile cloning clickfix credential theft cryptocurrency wallet darkweb forums hijackloader hvnc maas session hijacking silabrat
Tags
2026-06-10 asmcrypt browser profile cloning clickfix credential-theft cryptocurrency wallet darkweb forums hijackloader hvnc maas session hijacking silabrat
Related entities
5 indicators, 5 observables, 1 intrusion sets (apt), 3 malware

Description

is an advanced Remote Access Trojan offered as Malware-as-a-Service on since late 2025, developed by threat actor o1oo1 and sold for $5,000 monthly. This financially-motivated tool focuses on and cryptocurrency operations, featuring Hidden Virtual Network Computing for invisible remote control, to bypass session protections, and automated password cracking. The RAT bypasses Chrome App-Bound Encryption, performs , and includes keylogging, clipboard monitoring, and remote desktop capabilities. Distributed through phishing and campaigns with operator-hosted infrastructure, uses ChaCha20-Poly1305 encryption for command-and-control communications. The developer also offers , a companion crypter service, creating a complete malware bundle from evasion to execution and remote control.

External references