Group-IB reported that SilabRAT is being sold as a malware-as-a-service remote access trojan on Russian-language darkweb forums, with subscriptions advertised at $5,000 per month and linked to the Russian-speaking developer o1oo1. The malware has been observed in spam and ClickFix campaigns, where security tools often identify the packer as HijackLoader instead of the underlying payload, helping the RAT evade straightforward detection. Unlike centralized crimeware operations, SilabRAT uses operator-hosted infrastructure, allowing each buyer to run their own command-and-control server and keep victim data under their control.
SilabRAT is built for stealthy remote access, account takeover, and cryptocurrency theft. Group-IB said its features include HiddenVNC, browser profile cloning, cookie theft, a Chrome App-Bound Encryption bypass via GoogleChromeElevationService COM elevation, AMSI bypass, UAC bypass through ICMLuaUtil, persistence with Registry Run keys and Scheduled Tasks, keylogging, clipboard monitoring, remote desktop, payload delivery, and process execution. The malware also targets crypto users by stealing wallet artifacts, attempting wallet password cracking with harvested browser credentials, and supporting crypto-clipping, while planned updates reportedly include customizable Electron injection against applications such as Ledger Wallet and Trezor Suite.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On June 10, 2026, Group-IB published a technical analysis of SilabRAT, describing its MaaS model, links to developer “o1oo1,” operator-hosted infrastructure, and planned future development such as customizable Electron injection. The report highlighted stealth, account takeover, and crypto-theft functionality.
Group-IB said SilabRAT was observed in real-world spam and ClickFix campaigns, where antivirus products often identified the packer as HijackLoader instead of detecting the SilabRAT payload. The report also detailed the malware’s remote access, credential theft, and cryptocurrency-targeting capabilities.
Group-IB reported that SilabRAT had been sold as a Malware-as-a-Service on Russian-language darkweb forums since at least September 2025, with subscriptions advertised at $5,000 per month. The malware was associated with the Russian-speaking developer known as “o1oo1.”
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.