Also known as: Stately Taurus, Earth Preta, among other monikers, tracked as, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Orion Leaks, SnappyClient, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, Royal Ransomware
o1oo1 emerged in the late 2020s as a prolific malware author, offering its flagship RAT SilabRAT as a service to other cybercriminals for $5,000 per month. The tool is engineered with advanced evasion, featuring hidden VNC support, browser profile cloning, and automated wallet password cracking to maximize financial yield. Its command‑and‑control traffic is protected via ChaCha20‑Poly1305 encryption and stealthily masqueraded as regular web traffic through HTTP/HTTPS channels. The actor’s operational model blends initial access brokerage with the acquisition or compromise of third‑party cloud infrastructure—domains, hosting, container images—to achieve low‑troubleshoot persistence. Once inside a target environment, o1oo1 establishes local and domain accounts, hijacks Windows services, and expands lateral movement through Remote Desktop/SMB. It also exploits MFA weaknesses, steals web session cookies, and performs phishing campaigns to harvest credentials for Office 365, Google Workspace, and Exchange. Beyond data theft, o1oo1 engages in a range of financial‑threat tactics: ransomware extortion under the Royal Ransomware alias, business email compromise, crypto payouts via “pig‑butchering” wallets, and coordinated denial‑of‑service attacks against web endpoints and DNS to pressure victims into paying. The actor’s tools are modular—ranging from AsmCrypt crypter bundles to backdoored cloud images—allowing operators to tailor their delivery chains for maximum stealth and profit.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
o1oo1 is a financially‑motivated Russian‑speaking threat actor that develops and sells sophisticated remote access trojans—most notably SilabRAT (aka SnappyClient)—on underground marketplaces. The actor leverages stolen credentials, publicly hosted infrastructure, and legitimate web services for command‑and‑control while executing credential theft, cryptocurrency operations, and targeted denial‑of‑service attacks against both web and network services.
Goals & Targeting
o1oo1’s primary objective is monetary gain, achieved through credential harvesting, cryptocurrency mining/payout, ransomware deployment, and BEC schemes. Its targeting list spans critical infrastructure, financial services, government agencies, healthcare, and media organizations across a broad geographic footprint—including CN, RU, IN, UA, GB, DE, KE, IR, PK, BY, PL, TW, CA, AU, US, AE—favoring environments with high-value data or payment systems. By exploiting publicly available services and leveraging stolen credentials on platforms like Google, GitHub, and Twitter for C2, the actor avoids traditional perimeter defenses, thereby increasing reach and profitability.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
o1oo1 operates on a broker‑driven marketplace, shipping its RAT to a variety of affiliates who deploy it across global victim lists. Campaigns are typically rapid: reconnaissance via credential theft and C2 tunneling through legitimate services, followed by initial compromise using phishing or exploited remote services. The actor’s persistence tactics—creating local/domain accounts, substituting Windows service binaries, and implanting cloud images—indicate a focus on long‑term footholds for financial exploitation. Known attacks include ransomware drops under the Royal Ransomware alias, BEC campaigns against government contractors, and targeted denial‑of‑service assaults aimed at forcing ransom payments. Victim profiles range from medium‑sized enterprises to critical infrastructure actors with sophisticated security postures, suggesting that o1oo1 tailors its delivery vectors to bypass specific defenses. The actor’s use of commodity cloud resources for hosting command servers reduces detection risk and scales operations horizontally.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence provides a clear picture that o1oo1 is an active malware developer focused on financial gain, with concrete evidence of RAT development and underground distribution. However, details about the actor’s exact operational timeframe, precise victim selection criteria, and full technique coverage remain partial. Attribution confidence is moderate; further corroboration from incident reports or forensic analysis would strengthen understanding of the actor’s capabilities and campaign tactics.
No campaigns linked yet.
No observed data linked yet.
54
Techniques
45
Tools
0
Campaigns
39
IOCs
0
Observed Data
15
Tactics