SilabRAT Malware: The $5,000-a-Month Crypto-Hunting RAT Hiding Behind HijackLoader
ID: 97603faf-8afd-5e0b-8b00-467d8cfd0d26
STIX ID: report--97603faf-8afd-5e0b-8b00-467d8cfd0d26
Feed Name: securityonline.info
SilabRAT (SnappyClient) is a commercial Remote Access Trojan sold as a $5,000/month Malware-as-a-Service on Russian-language forums; it provides operators live access to infected machines, an AutoWallet module to steal cryptocurrency by reusing harvested passwords, Hidden VNC (HVNC) for invisible remote control, session hijacking to bypass MFA, anti-AV/anti-forensic techniques, encrypted communications, and persistence mechanisms. The malware is distributed via email spam and ClickFix social engineering, is paired with a crypter (AsmCrypt), and is actively evolving (author has teased targeting Electron-based wallet apps); Group-IB published a technical analysis and indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
