Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Stately Taurus, Earth Preta, among other monikers, tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Orion Leaks, SnappyClient, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Royal Ransomware

Description

o1oo1 emerged in the late 2020s as a prolific malware author, offering its flagship RAT SilabRAT as a service to other cybercriminals for $5,000 per month. The tool is engineered with advanced evasion, featuring hidden VNC support, browser profile cloning, and automated wallet password cracking to maximize financial yield. Its command‑and‑control traffic is protected via ChaCha20‑Poly1305 encryption and stealthily masqueraded as regular web traffic through HTTP/HTTPS channels. The actor’s operational model blends initial access brokerage with the acquisition or compromise of third‑party cloud infrastructure—domains, hosting, container images—to achieve low‑troubleshoot persistence. Once inside a target environment, o1oo1 establishes local and domain accounts, hijacks Windows services, and expands lateral movement through Remote Desktop/SMB. It also exploits MFA weaknesses, steals web session cookies, and performs phishing campaigns to harvest credentials for Office 365, Google Workspace, and Exchange. Beyond data theft, o1oo1 engages in a range of financial‑threat tactics: ransomware extortion under the Royal Ransomware alias, business email compromise, crypto payouts via “pig‑butchering” wallets, and coordinated denial‑of‑service attacks against web endpoints and DNS to pressure victims into paying. The actor’s tools are modular—ranging from AsmCrypt crypter bundles to backdoored cloud images—allowing operators to tailor their delivery chains for maximum stealth and profit.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Healthcare
Media
Education
Manufacturing
Telecommunications
Critical infrastructure
Construction
Information technology
Retail
Non profit
Hospitality
Transportation
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture

Targeted Countries / Regions

CN
RU
IN
UA
GB
DE
KP
IR
PK
BY
PL
TW
CA
AU
US
AE

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

o1oo1 is a financially‑motivated Russian‑speaking threat actor that develops and sells sophisticated remote access trojans—most notably SilabRAT (aka SnappyClient)—on underground marketplaces. The actor leverages stolen credentials, publicly hosted infrastructure, and legitimate web services for command‑and‑control while executing credential theft, cryptocurrency operations, and targeted denial‑of‑service attacks against both web and network services.

Goals & Targeting

o1oo1’s primary objective is monetary gain, achieved through credential harvesting, cryptocurrency mining/payout, ransomware deployment, and BEC schemes. Its targeting list spans critical infrastructure, financial services, government agencies, healthcare, and media organizations across a broad geographic footprint—including CN, RU, IN, UA, GB, DE, KE, IR, PK, BY, PL, TW, CA, AU, US, AE—favoring environments with high-value data or payment systems. By exploiting publicly available services and leveraging stolen credentials on platforms like Google, GitHub, and Twitter for C2, the actor avoids traditional perimeter defenses, thereby increasing reach and profitability.

Enhanced Description

Key Capabilities

  • Develop sophisticated RATs (SilabRAT/SnappyClient)
  • Facilitate lateral movement via Remote Services
  • Acquire or compromise third‑party hosting, domains, and cloud accounts
  • Exploit stolen email and cloud credentials for phishing, spam, and exfiltration
  • Leverage legitimate web platforms (Google, GitHub, Twitter, Dropbox, SendGrid) for covert C2 traffic
  • Create local/domain user accounts to maintain persistence
  • Target Exchange/Office 365/Google Workspace with stolen credentials
  • Execute endpoint denial‑of‑service on web services, email, DNS
  • Build and control botnets
  • Manage multiple cloud/email accounts for operational support
  • Social engineer phishing campaigns for credential compromise
  • Exploit vulnerabilities in remote services for lateral movement
  • Hijack Windows service binaries to gain higher privileges
  • Implant backdoored or malicious cloud/container images for persistence
  • Spoof browser/User‑Agent strings to blend traffic
  • Bypass multi‑factor authentication mechanisms
  • Engage in ransomware extortion, BEC, pig‑butchering, and crypto exploitation

MITRE ATT&CK Tactics

Initial Access
Lateral Movement
Resource Development
Credential Access
Persistence
Command and Control
Exfiltration
Impact
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1021
T1583
T1595
T1557
T1078
T1136
T1041
T1566
T1498
T1499
T1068
T1055
T1114
T1087
T1113
T1539
T1547
T1518
T1105
T1047
T1115
T1552
T1521
T1204
T1056
T1059
T1083
T1071
T1060
T1548
T1098
T1036
T1497
T1657

Software / Tooling

SilabRAT
SnappyClient
AsmCrypt
ClickFix
Toneshell
SocGholish
Royal Ransomware
Qilin
Netsupport Manager
BlackSuit
Conti
Cobalt Strike
Mythic
LummaC2
Hooks
AppDomainManager
GitHub
MSBuild
BITS
Netsh
Process Hollowing

Campaigns & Victims

o1oo1 operates on a broker‑driven marketplace, shipping its RAT to a variety of affiliates who deploy it across global victim lists. Campaigns are typically rapid: reconnaissance via credential theft and C2 tunneling through legitimate services, followed by initial compromise using phishing or exploited remote services. The actor’s persistence tactics—creating local/domain accounts, substituting Windows service binaries, and implanting cloud images—indicate a focus on long‑term footholds for financial exploitation. Known attacks include ransomware drops under the Royal Ransomware alias, BEC campaigns against government contractors, and targeted denial‑of‑service assaults aimed at forcing ransom payments. Victim profiles range from medium‑sized enterprises to critical infrastructure actors with sophisticated security postures, suggesting that o1oo1 tailors its delivery vectors to bypass specific defenses. The actor’s use of commodity cloud resources for hosting command servers reduces detection risk and scales operations horizontally.

IOC Patterns

  • Use of compromised credentials on public platforms (Google, GitHub, Twitter) for phishing or C2
  • Leverage legitimate third‑party services (cloud, web, email) for command & control or exfiltration
  • Creation of local/domain accounts to persist in victim environment
  • Endpoint denial‑of‑service traffic targeting web, DNS, and email services
  • HTTP User‑Agent spoofing to mimic benign traffic
  • MFA bypass tactics
  • Hijacking Windows service binaries via permission misuse
  • Backdoored cloud/container images for persistence

Recommended Actions

  • Restrict and monitor Remote Desktop/SMB access; enforce least‑privilege on remote services
  • Implement MFA on all email, cloud, and third‑party accounts; block suspicious credential reuse across domains
  • Audit creation of local/domain accounts and flag unexpected additions
  • Detect and block HTTP traffic to known C2 domains on legitimate cloud platforms
  • Rate‑limit and harden web endpoints against DoS attacks; use WAFs for SMTP/HTTP exposure
  • Establish network segmentation to limit lateral movement
  • Deploy anomaly detection on outbound traffic toward external services
  • Configure logging for Windows service binaries and permission changes
  • Conduct regular vulnerability scanning of remote services and patch promptly
  • Train staff on spearphishing threats and phishing email indicators

Suggested Tags

malware development
Russian-speaking actor
SilabRAT
SnappyClient
remote-services exploitation
initial-access broker
underground marketplace
infrastructure acquisition
cloud-account compromise
web-service C2
mail exfiltration
local-account creation
domain-account persistence
exfil over cloud storage
endpoint DoS
denial of service
account abuse
phishing
remote exploitation
service hijacking
MFA bypass
cloud persistence

Confidence Assessment

The available intelligence provides a clear picture that o1oo1 is an active malware developer focused on financial gain, with concrete evidence of RAT development and underground distribution. However, details about the actor’s exact operational timeframe, precise victim selection criteria, and full technique coverage remain partial. Attribution confidence is moderate; further corroboration from incident reports or forensic analysis would strengthen understanding of the actor’s capabilities and campaign tactics.

ATT&CK Techniques

Lateral Movement
1 technique
Reconnaissance
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: services
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. www.bitdefender.com — Cited by web research for: Orion Leaks
  4. www.group-ib.com — Cited by web research for: T1657
  5. redcanary.com — Cited by web research for: SocGholish
  6. attack.mitre.org — Cited by web research for: Process Hollowing
  7. https://www.cisa.gov — Cited by AI analysis.

Intel Summary

54

Techniques

45

Tools

0

Campaigns

39

IOCs

0

Observed Data

15

Tactics

Tags

Financial Targeting
Phishing
Backdoor / C2
Data Exfiltration
APT
Ransomware
Financial Fraud
malware-as-a-service
malware development
Russian-speaking actor
SilabRAT
SnappyClient
remote-services exploitation
initial-access broker
underground marketplace
infrastructure acquisition
cloud-account compromise
web-service C2
mail exfiltration
local-account creation
domain-account persistence
exfil over cloud storage
endpoint DoS
denial of service
account abuse
phishing
remote exploitation
service hijacking
MFA bypass
cloud persistence

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.