Skip to main content
Mallory
MalwareRansomwareUsed by 1 actor

SilabRAT

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
o1oo1

In this blog, we deep-dive into SilabRAT and look at some of its interesting capabilities.

via group ibgroup-ib.com
MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566PhishingEvidence1

Group-IB analysts have observed buyers of SilabRAT deploying it in email spam and ClickFix attack campaigns... Victims typically encounter a ClickFix prompt through three main methods: phishing, malicious advertisements, or visiting compromised websites.

Execution

3 techniques
T1053.005Scheduled TaskEvidence1

The second method utilizes Scheduled Tasks, allowing the malware to execute at predefined intervals or specific system events.

T1059Command and Scripting InterpreterEvidence1

From there, operators can task individual bots or groups – to launch HVNC sessions, trigger the stealer, execute payloads via the loader...

T1204.002Malicious FileEvidence1

In Group-IB’s observed case, the victim was compromised through the ClickFix social engineering technique.

Persistence

3 techniques
T1053.005Scheduled TaskEvidence1

The second method utilizes Scheduled Tasks, allowing the malware to execute at predefined intervals or specific system events.

T1546.015Component Object Model HijackingEvidence1

SilabRAT utilizes an additional DLL named “APPB.dll” to employ the widely utilized technique of COM elevation to bypass ABE, where it decrypts the key by creating an instance via the GoogleChromeElevationService.

T1547.001Registry Run Keys / Startup FolderEvidence1

The first leverages Registry Run keys to achieve execution at user logon.

Privilege Escalation

5 techniques
T1053.005Scheduled TaskEvidence1

The second method utilizes Scheduled Tasks, allowing the malware to execute at predefined intervals or specific system events.

T1055.001Dynamic-link Library InjectionEvidence1

The author has written in forum posts future plans to implement fully customizable injection capabilities targeting Electron-based applications... injecting malicious code directly into their Electron processes.

T1546.015Component Object Model HijackingEvidence1

SilabRAT utilizes an additional DLL named “APPB.dll” to employ the widely utilized technique of COM elevation to bypass ABE, where it decrypts the key by creating an instance via the GoogleChromeElevationService.

T1547.001Registry Run Keys / Startup FolderEvidence1

The first leverages Registry Run keys to achieve execution at user logon.

T1548.002Bypass User Account ControlEvidence1

When necessary, SilabRAT attempts to bypass Windows UAC (User Account Control) by elevating privileges using the ICMLuaUtil COM interface.

Stealth

1 technique
T1055.001Dynamic-link Library InjectionEvidence1

The author has written in forum posts future plans to implement fully customizable injection capabilities targeting Electron-based applications... injecting malicious code directly into their Electron processes.

Credential Access

4 techniques
T1056.001KeyloggingEvidence1

These capabilities include keylogging functionality to capture user keystrokes...

T1539Steal Web Session CookieEvidence1

Session hijacking is often more effective than password theft because it compromises an active authenticated session... Traditionally, session hijacking is achieved via stealing cookies. | Traditionally, session hijacking is achieved via stealing cookies. It is an old school technique where an attacker steals active session cookies and imports it into their own browser to impersonate the victim.

T1555Credentials from Password StoresEvidence1

Beyond simply collecting cryptocurrency wallet data and stored credentials, the panel also advertises functionality that assists buyers in automatically cracking wallet passwords. This is achieved by leveraging passwords harvested from the victim’s browser data.

T1555.003Credentials from Web BrowsersEvidence1

This is achieved by leveraging passwords harvested from the victim’s browser data... Once initialized, it invokes the DecryptData method to decrypt the “ app_bound_encrypted_key” which will then be used to decrypt the encrypted cookies.

Lateral Movement

1 technique
T1021.005VNCEvidence1

It supports a remote desktop via TightVNC that allows the operator to monitor the victim’s desktop.

Collection

2 techniques
T1056.001KeyloggingEvidence1

These capabilities include keylogging functionality to capture user keystrokes...

T1115Clipboard DataEvidence1

...and also clipboard monitoring, and clipping.

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

Additional modules enable remote process execution and downloading of further payloads, allowing attackers to further deploy additional malware after initial compromise.

Other

1 technique
T1562.001Disable or Modify ToolsEvidence1

The current implementation of the defense evasion technique is limited to straightforward bypasses targeting the Anti-Malware Scan Interface (AMSI). Specifically, the method employs a simplified approach to interfere with the AmsiScanBuffer and AmsiScanString functions...

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.