Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 37 IP / 17 hostnames
SalatStealer is a Windows-focused Go-based malware-as-a-service infostealer that also incorporates substantial remote-access functionality.
Profile source: Mallory opens in a new tabSALATSTEALER
SalatStealer is a Windows-focused Go-based malware-as-a-service infostealer that also incorporates substantial remote-access functionality. It has been described under the NyashTeam or WebRAT branding and has been observed in criminal distribution ecosystems as well as in targeted campaigns against Ukrainian entities. The malware is commonly packed or disguised to hinder analysis and uses encrypted configuration data, runtime decryption, and resilient command-and-control resolution mechanisms including DNS-over-HTTPS and, in newer variants, TON blockchain DNS. Communications have been observed over WebSocket secured with TLS, with QUIC or HTTP/3 support used for bulk data transfer.
Its core purpose is theft of high-value user data. SalatStealer targets credentials, cookies, browser databases, local state material, authentication tokens, and cryptocurrency wallet data from a wide range of Chromium- and Gecko-based browsers. It also targets browser extensions associated with digital-asset wallets, extracts data from messaging and gaming applications, and can collect clipboard contents relevant to cryptocurrency theft. Reported collection includes browser logins, session material, wallet artifacts, Telegram and Discord data, Steam-related data, screenshots, and other host-resident information suitable for account takeover and financial fraud.
Beyond classic infostealer behavior, SalatStealer includes RAT capabilities such as arbitrary command execution, interactive shell access, screen capture, desktop recording, webcam capture, microphone capture, keylogging, file download, process control, hidden desktop interaction, and SOCKS5 or peer-to-peer proxy functionality. These features enable both surveillance and broader post-compromise utility. Observed abuse of FFmpeg through the Windows DirectShow interface indicates support for covert multimedia device discovery and active video capture on infected hosts.
The malware employs multiple defensive and privilege-related techniques. Reported behaviors include adding Microsoft Defender exclusions, persistence through autorun mechanisms and scheduled tasks, COM-based elevation abuse to bypass browser protections, token manipulation, LSASS targeting, and anti-analysis measures such as misleading packer artifacts and runtime-obfuscated configuration. It has also been associated with process injection or hollowing in broader delivery chains and with self-deletion or cleanup behaviors.
Observed delivery has been diverse and strongly aligned with commodity cybercrime tradecraft. SalatStealer has been distributed via cracked software, game cheats, phishing and spearphishing campaigns, ClickFix-style lures, malicious archives containing executables or shortcuts, compromised websites, fake meeting-themed landing pages, and pay-per-install botnet ecosystems such as Amadey. It has also been linked to campaigns abusing GitHub-hosted payloads and to exploitation of CVE-2025-8088 in attacks impersonating Ukrainian government institutions.
Victim targeting spans broad criminal monetization as well as regionally focused operations. SalatStealer has been observed in campaigns targeting Ukrainian government institutions and Ukrainian-speaking organizations, while commodity distribution activity indicates wider global targeting of consumers and enterprises for credential theft, session hijacking, and cryptocurrency compromise. Its combination of infostealing, surveillance, and remote-access features makes it useful both as a standalone theft platform and as an enabling tool within larger intrusion chains.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6747147c5ba29975a557d88cd22114478890a0a0a613f36512dcb730e4efe965 944a6ff7edb3991a3f60e19d26f23ad21054adc53109cfcdbb5d101a84a7971b dd17e871204619a3de34126e366221b64e684ec13e24dfc871698abe343acbff fbf4ef28c4b49c6304d23a738afabf8981590eae8585834bf24e3c7e87163c1a 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 6ff59d49647c897e8c134519f5eb73ff53bd55386a24c55058e7427598d5a754 8e2b78e7c586e36dc3b27c78466fad735f86cdd9b4e7ecbc4c650d934a9a176b b7a06c7dd0943016ee68b5c14ec8a20578df56f9d9fa5f6ea73df6daa5211c07 d00a0806b145423c459a4df53471965dc36f82ec5d5a5d4d108e0a7a1ce09d7b Reported operators
The group's arsenal includes an infostealer named SHADOWSNIFF, a Malware-as-a-Service (MaaS) variant called SALATSTEALER, and DEAFTICK, a Go-based backdoor strain.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.