o1oo1 is a Russian-speaking cybercriminal malware developer and vendor associated with SilabRAT, a remote access trojan marketed as a malware-as-a-service offering on Russian-language underground forums since at least 2025. The actor has been active in underground communities since late 2020 and has also been linked to the separate AsmCrypt crypter service. Earlier activity attributed to o1oo1 includes trading bulk SMTP credentials, exchanging leaked data, and participating in carding and phishing discussions, indicating a financially motivated criminal profile. SilabRAT is designed for stealthy remote access, account takeover, and cryptocurrency theft. Its capabilities include hidden remote desktop control through hidden VNC, browser profile cloning to evade session protections, cookie decryption and theft through a Chrome App-Bound Encryption bypass, credential extraction, keylogging, clipboard monitoring, payload downloading, remote process execution, and persistence via autorun mechanisms and scheduled tasks. The malware also incorporates defense-evasion features such as AMSI interference, anti-forensics, and UAC bypass techniques. It has been observed in spam and ClickFix-driven intrusion chains, and its packaging has at times caused security products to identify the loader rather than the final payload. A notable focus of o1oo1’s tooling is cryptocurrency theft. SilabRAT supports theft of wallet artifacts, automated attempts to recover wallet passwords using harvested browser passwords, and crypto-clipping functionality. The developer has also indicated plans to expand targeting of cryptocurrency-related desktop applications through customizable injection features. SilabRAT is operated in an operator-hosted model in which customers run their own command-and-control infrastructure and retain victim data, consistent with a commercial cybercrime service rather than a centrally run espionage platform.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.