Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The Security Ledger

The Security Ledger Vendor Cyber Rating & Cyber Score

securityledger.com

Security Ledger is an independent security news website that explores the intersection of cyber security with business, commerce, politics and everyday life. Security Ledger provides well-reported and context-rich news and opinion about computer security topics that matter in our IP-enabled homes, workplaces and daily lives.


SL A.I CyberSecurity Scoring

SL
Company Information
Website:https://www.securityledger.com
Employees number:1
Number of followers:839
NAICS:519131
Industry Type:Online Audio and Video Media
Homepage:securityledger.com
SL Risk Score (AI oriented)
Between 700 and 749
logo
SLOnline Audio and Video Media
Updated:
10/06/2026
736/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SL Global Score (TPRM)
xxxx
logo
SLOnline Audio and Video Media
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SL
SLModerate
Current Score
736Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
736Before Incident
MAY 2026
735Before Incident
APRIL 2026
735Before Incident
MARCH 2026
734Before Incident
FEBRUARY 2026
734Before Incident
JANUARY 2026
734Before Incident
DECEMBER 2025
733Before Incident
NOVEMBER 2025
732Before Incident
OCTOBER 2025
750Before Incident
Cyber Attack
01 Oct 2025SL
Ledger and Trezor: New SilabRAT Trojan Hijacks Sessions to Steal Crypto

SilabRAT: A Stealthy Crypto-Draining Malware Emerges as MaaS

731After Incident
CRITICAL-19
TRETHE1781108679
SilabRAT: A Stealthy Crypto-Draining Malware Emerges as MaaS A new remote access trojan (RAT), SilabRAT, has surfaced on dark web forums, designed to bypass passwords and multi-factor authentication (MFA) by hijacking active user sessions to drain cryptocurrency. First advertised in late 2025 by a Russian-speaking threat actor known as o1oo1, the malware is offered as a malware-as-a-service (MaaS) for $5,000 per month. Buyers who often distribute it via email spam and ClickFix lures have reported success rates, with over 90% of infected machines remaining online during month-long campaigns. SilabRAT evades detection by disguising itself as HijackLoader, a known packer, rather than its true payload. Its standout features include: - Hidden Virtual Network Computing (HVNC): Operators control infected machines without visible windows or cursor movement, making activity appear as legitimate user sessions. - Browser-Profile Cloning: The malware copies entire browser profiles including extensions, storage, and device fingerprints to an attacker’s system, allowing stolen sessions to persist even after logouts. A Target.dll module ensures the cloned profile loads seamlessly on the victim’s device. The malware’s primary goal is cryptocurrency theft. A background module scans for wallets upon infection, attempting to crack passwords using credentials harvested from the victim’s browser. It bypasses Chrome’s App-Bound Encryption via a COM-elevation technique and includes a clipboard clipper to swap wallet addresses mid-transaction. Additional capabilities include: - Keystroke logging and clipboard monitoring - Remote desktop access via TightVNC - A UAC bypass previously used by LockBit and BlackMatter - Persistence through registry keys or scheduled tasks Group-IB, which analyzed the threat, warns that SilabRAT’s developer plans to expand its reach by injecting code into Electron-based wallet apps, such as Ledger Live and Trezor Suite. While traditional defenses like MFA and patching can help, the malware’s session-hijacking tactics allow it to bypass even secured logins.
INCIDENT DETAILS -
TYPE
Malware (RAT)
MOTIVATION
Financial gain (cryptocurrency theft)
IMPACT
Financial Loss: Cryptocurrency theftBrowser profilesWallet credentialsKeystrokesClipboard dataSystems Affected: Infected machines (Windows)Operational Impact: Remote control of infected machines via HVNCIdentity Theft Risk: High (session hijacking, PII exposure)Payment Information Risk: High (cryptocurrency wallet theft)
DATA BREACH
Browser profilesWallet credentialsKeystrokesClipboard dataSensitivity Of Data: High (PII, financial data)Data Exfiltration: Yes (cloned browser profiles, wallet data)Data Encryption: Bypassed (Chrome's App-Bound Encryption)Personally Identifiable Information: Yes (browser profiles, session data)
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SL ?
?
What was SL's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SL's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SL's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SL's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SL's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SL's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SL's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SL's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SL's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SL's A.I Rankiteo Cyber Score in August 2025 ?
?
What was SL's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on SL's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SL ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SL's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?