Attackers are constantly searching for new tools that provide stealth, stability, and stronger monetization opportunities.
Our latest research examines
#SilabRAT, a Malware-as-a-Service platform sold on underground forums that combines credential theft, browser profile cloning, HVNC, Chrome App-Bound Encryption bypass techniques, and cryptocurrency-focused capabilities into a single offering.
Key findings:
🔹 SilabRAT has been marketed on underground forums since late 2025 for $5,000/month
🔹 Leverages HVNC for invisible interaction with victim systems; other session access options include browser profile cloning, cookie theft
🔹 Includes functionality to bypass Chrome App-Bound Encryption (ABE) and extract protected browser data
🔹 Features automated
#cryptocurrency wallet targeting and password recovery capabilities
🔹 Observed in real-world campaigns leveraging ClickFix
#socialengineering techniques
As cybercriminals move beyond simple credential theft toward full session compromise, understanding emerging
#RAT capabilities is critical for defenders.
🔗 Read the full analysis:
link.group-ib.com/4xluZub