SilabRAT, What's Your Power?

June 10, 2026, 2:01 p.m.

Description

SilabRAT is an advanced Remote Access Trojan offered as Malware-as-a-Service on Darkweb forums since late 2025, developed by threat actor o1oo1 and sold for $5,000 monthly. This financially-motivated tool focuses on credential theft and cryptocurrency operations, featuring Hidden Virtual Network Computing for invisible remote control, browser profile cloning to bypass session protections, and automated cryptocurrency wallet password cracking. The RAT bypasses Chrome App-Bound Encryption, performs session hijacking, and includes keylogging, clipboard monitoring, and remote desktop capabilities. Distributed through phishing and ClickFix campaigns with operator-hosted infrastructure, SilabRAT uses ChaCha20-Poly1305 encryption for command-and-control communications. The developer also offers AsmCrypt, a companion crypter service, creating a complete malware bundle from evasion to execution and remote control.

Date

  • Created: June 10, 2026, 11:58 a.m.
  • Published: June 10, 2026, 11:58 a.m.
  • Modified: June 10, 2026, 2:01 p.m.

Indicators

  • fb56e66920c84ef9e51db0ea23144f5755daef97cbff8613b05ab56d0dc9d623
  • 79f8da9f9fb4ac7c16d9c210f1f6ef418357a3e7bf602b1dd03a490596fa58c5
  • 3a6adbe0081b2488e0f137496e92591e0c29148154b2d99faadab9cc435b879b
  • fbce30a0c852972fdc24f1b6a7c270512a50ef1a7c6c88c88b92a2dcbdfdd023
  • 91.199.163.124

Attack Patterns

  • SilabRAT
  • Hijackloader
  • AsmCrypt
  • o1oo1