SilabRAT turns the browser session into the thing attackers steal. Once the victim is already logged in, passwords and MFA stop being the last line of defense, because the malware is built to reopen that live session from another machine.
Group-IB says the tool has been sold since late 2025 as a $5,000-a-month malware-as-a-service package by the actor known as o1oo1. Buyers run their own spam and ClickFix campaigns, and the malware copies browser profile data, uses hidden VNC, and is aimed at crypto wallets and browser-tied accounts, with Ledger Live and Trezor Suite singled out as future targets.
The practical risk is that session theft can scale as a product, not just as a custom attack. That pushes browser state itself into the attacker’s target set, and a compromised workstation can still be enough to drain funds even when the login step was already completed.