Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Elon Musk battles Grok safety claims before SpaceX debut

June 13, 2026

How $48 mln vanished from Tron to Monero before Tether could stop it

June 13, 2026

Goldman Sachs Sees Fed Delaying Rate Cuts This Year – Here’s When the Next One Is Coming

June 13, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»New SilabRAT Trojan Hijacks Sessions to Steal Crypto
New SilabRAT Trojan Hijacks Sessions to Steal Crypto
Security and Privacy

New SilabRAT Trojan Hijacks Sessions to Steal Crypto

June 10, 2026No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A new remote access trojan sold on dark web forums has been built to drain cryptocurrency, hijacking victims’ logged-in sessions to slip past passwords and multi-factor checks.

Dubbed SilabRAT, the malware has been detailed in new analysis from Group-IB, which found it advertised since late 2025 as a malware-as-a-service (MaaS) offering at $5000 a month.

Its developer, a Russian-speaking actor known as o1oo1, also sells a code-obfuscation tool called AsmCrypt and discounts buyers who take both.

Buyers run their own campaigns, often spreading SilabRAT through email spam and ClickFix lures, and antivirus tools frequently log it as the HijackLoader packer rather than the payload. One operator claimed more than 90% of infected machines stayed online across a month-long campaign.

Read more on session-stealing malware: New ‘Storm’ Infostealer Remotely Decrypts Stolen Credentials

Hidden Control and Cloned Browsers

Two features set SilabRAT apart. The first, a hidden virtual network computing (HVNC) solution, allows an operator to control a machine with no visible windows or cursor movement. Because the activity comes from the victim’s own device and IP address, security tools often treat it as a legitimate session.

The second, browser-profile cloning, goes beyond stealing cookies. Modern sites tie sessions to a device fingerprint or IP, so SilabRAT copies the entire browser profile, including extensions, storage and fingerprinting traits, to the attacker’s system to revive the session intact.

The two interlock: a bundled DLL, Target.dll, hooks low-level file calls so the browser opens the cloned profile, letting the hidden session run on the victim’s live data while the real desktop stays untouched.

Built to Empty Crypto Wallets

The payoff is cryptocurrency. A background module runs continuously, hunting for wallets on new infections and trying to crack their passwords with credentials lifted from the victim’s browser, working through a built-in list of supported wallets.

See also  Proofpoint: We Block Up to Two Million Extortion Emails Daily

To reach those browser secrets, SilabRAT bypasses Chrome’s App-Bound Encryption with a COM-elevation technique, while a clipboard clipper can swap a copied wallet address for the attacker’s mid-transaction.

It pairs those with the usual commodity-RAT toolkit:

  • Keystroke logging and clipboard capture

  • Remote desktop access over TightVNC

  • A user account control bypass also used by LockBit and BlackMatter

  • Persistence via registry keys or scheduled tasks

Group-IB expects the crypto focus to deepen, pointing to the developer’s stated plan to inject code into Electron-based wallet apps such as Ledger Live and Trezor Suite.

To blunt the threat, the company urged defenders to enforce multi-factor authentication (MFA), keep Chrome patched and step up phishing and web filtering, while cautioning that a hijacked session can still walk past a password prompt.

Source link

Crypto Hijacks sessions SilabRAT Steal Trojan
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto News Today: AlphaPepe Unveils AlphaSwap Early Access as Bitcoin Price Prediction Eyes $250,000

June 13, 2026

VanEck bets BNB’s real-world usage can stand out in a crowded crypto ETF market

June 13, 2026

Bitcoin hit bottom at $59,000 marking end to the crypto winter, says Standard Chartered analyst

June 12, 2026

Nigeria Senate Passes Bill to Regulate Crypto and Revive Textile Industry

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Northlands College Unveils Metaverse Campus

October 11, 2023

Ethereum presents selling opportunity, should you take up the offer?

August 2, 2023

Amazon Enhances Web3 Development with New Blockchain Tools

July 28, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Elon Musk battles Grok safety claims before SpaceX debut

June 13, 2026

How $48 mln vanished from Tron to Monero before Tether could stop it

June 13, 2026

Goldman Sachs Sees Fed Delaying Rate Cuts This Year – Here’s When the Next One Is Coming

June 13, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,872.000.24%
  • ethereumEthereum(ETH)$1,676.580.21%
  • tetherTether(USDT)$1.000.07%
  • binancecoinBNB(BNB)$605.87-0.12%
  • usd-coinUSDC(USDC)$1.000.02%
  • rippleXRP(XRP)$1.150.51%
  • solanaSolana(SOL)$67.821.49%
  • tronTRON(TRX)$0.3165681.48%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.07%
  • dogecoinDogecoin(DOGE)$0.0878161.57%