# Week of Threats: Infostealers, Advanced RATs, and Nation-State Campaigns Converge on Tech Sector


A convergence of high-volume credential theft, sophisticated malware-as-a-service operations, and nation-state attacks targeting the tech industry defines the cybersecurity landscape as of mid-2026. This week's threat landscape reveals not just the scale of attacks, but a troubling professionalization of the criminal ecosystem—from browser-cloning RATs to social engineering targeting security clearance holders.


## The Infostealer Epidemic: 3.3 Billion Records in Circulation


New research from Flashpoint paints a dire picture of the credential theft economy. Over 11.1 million devices were infected with infostealer malware in 2025 alone, fueling a black market supply of more than 3.3 billion stolen credentials, session cookies, cloud tokens, and other identity data now actively circulating across darknet marketplaces and underground forums.


The scale is staggering: there are now over 30 unique infostealer strains being actively marketed and sold, demonstrating how mature the malware-as-a-service ecosystem has become. The most prolific strains include:


| Malware Family | Activity Level | Primary Function |

|---|---|---|

| Lumma | High | Credential and session theft |

| Acreed | High | Browser data extraction |

| Rhadamanthys | High | Multi-purpose infostealer |

| Vidar | High | Financial data targeting |

| StealC | High | Widespread credential theft |


Geographic hotspots for infostealer infections remain concentrated in developing economies with large outsourcing workforces: India, Brazil, Indonesia, Vietnam, and the Philippines top the list, followed by the United States. This pattern suggests attackers are deliberately compromising supply chain workers—developers, IT administrators, and system integrators with access to enterprise networks.


## The Evolution of Malware-as-a-Service: SilabRAT


The professionalization of the cybercriminal ecosystem reaches new heights with the emergence of SilabRAT, an advanced remote access trojan advertised at $5,000 per month on darknet forums by a Russian-speaking developer operating under the alias "o1oo1."


### Technical Capabilities


SilabRAT represents a significant evolution in RAT functionality. Unlike commodity malware, this tool combines multiple attack vectors:


  • Hidden Virtual Network Computing (HVNC): Provides remote control capabilities while masking the attacker's presence from security tools
  • Browser Profile Cloning: Replicates a target's complete browser environment—including user agents, extensions, stored data, and fingerprinting attributes—allowing attackers to impersonate users to web services
  • Cryptocurrency Detection: Identifies wallet addresses and extracts crypto-related artifacts for theft
  • Credential Targeting: Focuses specifically on financial account credentials, marking a shift toward high-value theft rather than mass harvesting

  • ### Delivery and Distribution


    SilabRAT is distributed via ClickFix campaigns—a social engineering attack that tricks users into running malicious code—paired with Hijack Loader, a loader malware that extracts and executes the RAT payload. This combination allows attackers to maintain plausible deniability while targeting specific high-value victims.


    The developer, "o1oo1," has been operating in the underground since late 2020 and previously managed AsmCrypt, another malware-as-a-service offering. The $5,000 monthly subscription model reflects the stability and sophistication of the tool—pricing comparable to legitimate security software.


    ## Nation-State Focus on Tech Sector: North Korean "Famous Chollima"


    CrowdStrike's latest threat intelligence report reveals a sobering statistic: North Korean threat actors accounted for 47% of all state-sponsored hands-on-keyboard operations against the technology sector between April 2025 and March 2026.


    The primary campaign, attributed to Famous Chollima (also known as the "IT worker campaign" or "Contagious Interview" operation), specifically targets:


  • Software developers
  • System administrators
  • DevOps engineers
  • Cloud architects
  • Security professionals

  • ### Attack Methodology


    Rather than relying on exploit kits or mass malware campaigns, Famous Chollima focuses on social engineering and fraudulent employment solicitation. The group creates fake recruiting profiles and job offers targeting tech workers in North America, Europe, and Asia. Once engagement begins, attackers attempt to:


    1. Build rapport and credibility over weeks or months

    2. Request access to company systems "for project demonstration"

    3. Obtain or create legitimate credentials

    4. Establish persistence and move laterally within target networks


    This "hands-on-keyboard" approach is labor-intensive but highly effective, as it bypasses purely technical defenses and exploits human trust.


    ## Chinese Intelligence Operations: 13 Domains Seized


    The U.S. Department of Justice has seized 13 internet domains masquerading as legitimate consulting companies. These domains were used by alleged Chinese intelligence operatives to target U.S. persons with security clearances, including current and former government officials with access to classified and sensitive information.


    ### Social Engineering at Scale


    The operation relied on simple but effective social engineering: offers of easy money for vague "consulting" work. Targets were typically approached via LinkedIn or email with promises of $5,000–$15,000 for short-term consulting engagements. Once victims engaged, they were asked to:


  • Discuss ongoing classified projects
  • Share technical details about government systems
  • Provide insights into organizational security practices
  • Obtain sensitive documents "for reference"

  • As Assistant Attorney General John A. Eisenberg stated, "These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty-bound to protect."


    ## Cross-Cutting Implications for Organizations


    Several alarming themes emerge from this week's threat landscape:


    1. Hybrid Attack Chains

    Modern campaigns blend credential theft, malware-as-a-service, social engineering, and nation-state targeting. A developer infected with Lumma infostealer can unknowingly expose credentials that enable a Famous Chollima recruiter to gain enterprise access.


    2. The Outsourcing Vulnerability

    Attackers deliberately target contractor networks, supply chain workers, and outsourced development teams. Their compromise provides lateral access into enterprise networks.


    3. Nation-States Adopting Cybercriminal Playbooks

    Famous Chollima's use of fake job postings and social engineering mirrors techniques historically associated with financial fraud groups—indicating a convergence between state-sponsored and criminal methodologies.


    4. The Credential Economy

    3.3 billion stolen records represent not just past breaches, but an ongoing inventory of tradeable identity assets. A compromised password from 2024 may still work in 2026.


    ## Recommendations for Organizations


    Immediate Actions:

  • Implement passwordless authentication (FIDO2 security keys) for high-value accounts
  • Enable continuous credential risk monitoring to detect compromised accounts in real-time
  • Review employee engagement processes—verify job opportunities through official company channels
  • Require multi-factor authentication on all external-facing systems

  • Medium-Term:

  • Assume compromise of contractor and supply chain credentials; segment their network access accordingly
  • Conduct social engineering awareness training focused on financial offers and recruitment fraud
  • Audit access logs for unusual lateral movement patterns consistent with Famous Chollima's post-compromise behavior

  • Long-Term:

  • Invest in behavioral anomaly detection to identify "hands-on-keyboard" intrusions
  • Consider zero-trust architecture principles, particularly for contractors and remote workers
  • Establish threat intelligence partnerships to receive alerts on domain seizures and known threat indicators

  • ---


    ## HackWire Analysis


    What's notable this week isn't any single headline—it's the operational maturity and normalization of what used to be exotic attacks. A $5,000-per-month RAT with browser cloning is now commodity infrastructure. Nation-state operators running fake LinkedIn recruiter accounts. 11 million devices feeding a credential marketplace. This isn't the bleeding edge of cybercrime anymore; it's the infrastructure layer.


    The more unsettling pattern: each attack category is operating independently but in parallel. An infostealer victim in Brazil may have no connection to Famous Chollima's U.S. targeting, yet both feed the same underground economy. The developer infected with Lumma doesn't know their credentials will be used to compromise a tech company later. The security clearance holder responding to a fake consulting offer doesn't realize they're talking to an intelligence service. These attacks work because they're not coordinated—they're parallel threats that only intersect at the defender's desk when incidents occur.


    For security leaders, the implication is clear: assume your environment contains multiple simultaneous attack vectors at different stages. Credential theft, insider recruitment, and malware-as-a-service access may all be active against your organization simultaneously. Detection requires looking not just for sophisticated exploits, but for mundane indicators: unusual credential use, suspicious hiring inquiries, and behavioral anomalies from supply chain partners. The threat isn't just smarter—it's broader.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)