logo

SilabRAT, What’s Your Power?

ID: 5b71e827-d93a-5de5-9853-a27267083a4e

STIX ID: report--5b71e827-d93a-5de5-9853-a27267083a4e

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

...
...

**Executive summary:** This Group‑IB analysis profiles SilabRAT, a commercially marketed RAT/MaaS sold on Russian‑language darknet forums by actor “o1oo1”; SilabRAT provides HVNC-based hidden remote control, browser profile cloning and cookie theft to enable session hijacking, automated crypto‑wallet credential cracking, an operator web panel with bot management and modular stealers, and technical evasion (AMSI hooks, crypter compatibility) — with observed real‑world deployments via ClickFix phishing and other campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.