SilabRAT Trojan Hijacks Sessions to Steal Cryptocurrency (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- SilabRAT is sold as MaaS for $5000/month by developer o1oo1.
- Uses HVNC and browser cloning to hijack sessions, evading MFA.
- Targets cryptocurrency via wallet cracking, clipboard clipping, and planned app injection.
"A new remote access trojan sold as malware-as-a-service (MaaS) uses hidden virtual network computing (HVNC) and browser profile cloning to hijack logged-in sessions and steal cryptocurrency. Priced at $5000 per month and developed by a Russian-speaking actor, the malware bypasses passwords and multi-factor authentication by operating from the victim's own device and IP address."
no comments yet.