—
title: “ThreatsDay: 3.3 Billion Credentials, a 5k RAT, and North Korea’s Favorite Target”
author: Victor Kane
date: 2026-06-05
category: Startups
excerpt: The weekly threat roundup covers the biggest stories: 3.3 billion stolen credentials in circulation, a 5,000-a-month RAT with browser cloning, and North Korea accounting for nearly half of state-sponsored tech sector intrusions.
—

A few things happened this week that are worth knowing about.

**3.3 billion credentials in circulation**

Flashpoint published an analysis of the infostealer economy. More than 11 million devices were infected last year, producing over 3.3 billion stolen credentials and cloud tokens now circulating across illicit markets. The top strains are Lumma, Vidar, and StealC. India, Brazil, and the United States were the most affected countries. There are over thirty unique infostealer strains actively for sale. The malware-as-a-service market is mature, accessible, and growing.

**SilabRAT: a 5,000-a-month credential thief**

A threat actor using the handle “o1oo1” has been selling a remote access trojan called SilabRAT since September 2025. The pricing is 5,000 dollars per month. Group-IB documented its capabilities. It uses Hidden Virtual Network Computing for remote control. It clones browser profiles including user agents, extensions, storage, and fingerprinting attributes to the attacker’s machine. It identifies wallet addresses and extracts cryptocurrency artifacts. Delivery is through ClickFix campaigns using Hijack Loader. The developer has been active since 2020 and previously ran a service called AsmCrypt.

**North Korea’s favorite target**

CrowdStrike released data on state-sponsored hands-on-keyboard intrusions against the tech sector. A North Korean group known as Famous Chollima accounted for 47 percent of all such operations between April 2025 and March 2026. Their method is the Contagious Interview campaign. They apply for jobs at tech companies using fake identities, go through the interview process, and use the access they gain during onboarding to steal source code and credentials. North America, Europe, and Asia are their primary targets.

**Thirteen domains seized**

The Department of Justice seized thirteen domains that were masquerading as consulting companies. They were used to target US security clearance holders through platforms like Upwork, Expertia AI, and Hubstaff Talent. The approach is straightforward: advertise generic consulting jobs, recruit candidates with access to classified information, then pressure them to share sensitive data in exchange for cryptocurrency payments. The Five Eyes alliance issued a related warning about China using LinkedIn to target security personnel.

**What this pattern tells you**

The common thread across all four stories is that the attackers are not breaking new technical ground. They are scaling existing methods. The credential market is industrialized. The RAT market is SaaS-ified. The state-sponsored operations are using job boards as attack vectors. The defenses that worked a year ago are still mostly effective. The problem is that the volume of attacks has increased faster than the adoption of those defenses.