Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 2, 2026
- Feed role
- C2 / Distribution
- Host form
- 101 IP / 60 hostnames
SalatStealer, also marketed as WebRAT, is a Windows-focused Go-based malware family combining extensive information-stealing functionality with remote-access-trojan capabilities.
Profile source: Mallory opens in a new tabSALATSTEALER
SalatStealer, also marketed as WebRAT, is a Windows-focused Go-based malware family combining extensive information-stealing functionality with remote-access-trojan capabilities. It is associated with the Russian-speaking NyashTeam malware-as-a-service operation and has been distributed through phishing lures, ClickFix social engineering, compromised websites, malicious archives, pirated software, gaming cheats, and pay-per-install campaigns including Amadey activity. The malware targets browser credentials, cookies, session data, authentication tokens, cryptocurrency wallets and browser extensions, messaging-application data, gaming-platform tokens, clipboard contents, and system information. It can bypass Chromium App-Bound Encryption to recover protected browser data. SalatStealer supports remote command execution, reverse-shell access, file operations, screen, webcam, microphone, and desktop capture, keylogging, hidden-desktop interaction, SOCKS5 proxying, process control, privilege-related token operations, and LSASS targeting. It can establish persistence and impair Microsoft Defender protections. Recent variants resolve command-and-control infrastructure dynamically through TON blockchain DNS, with DNS-over-HTTPS fallback, and use encrypted WebSocket communications and QUIC-capable data transfer to complicate network-based disruption and detection.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095d 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 508e710d673802a532798e7dffa3aefcfb36eff0acef1620b8614917ac62e53e 8d793a16bf2e7153df21e2ede4b0baf6e080596073b27ecbeac6613b6a68b8d8 11e9209e824c97be6fd84e97a7c7582a30788af83635288b595bce1cfdad166d 3e97680e06a1593784588bb0e7b98ff1a5cb4809eee5aeb149840017f5714e45 5ce9106daa1c115c2803c0d86b28fdf29e8d252d1a8451618a828d373b2bc21c 6da03d103d6d73e1dd8e4b9719bd030e69bcf192098613ed25e85f65da2c735d a672d76b629fe6131b5ac4f8920712846eeaf0b05d890218ec999801dd88ddea Reported operators
The group's arsenal includes an infostealer named SHADOWSNIFF, a Malware-as-a-Service (MaaS) variant called SALATSTEALER, and DEAFTICK, a Go-based backdoor strain.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.
Exploited software
MITRE ATT&CK
Reporting
Researchers reconstructed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras, with the largest concentration of affected devices in Ukraine and Russia. The operation was pieced together from an exposed directory on 154.86.119.60 containing the operatorβs tooling, logs, source code, and staging files. According to the report, the attackers used three parallel access paths: credential brute forcing on TCP/37777, exploitation of CVE-2021-33044 and CVE-2021-33045, and abuse of Dahuaβs P2P cloud relay to reach cameras by serial number. Researchers said the relay path relied on cloud-issued session tokens obtainable through fixed SDK credentials embedded in Dahua clients, enabling unauthenticated access through that channel. The operators also installed a persistent backdoor account, p2pwn / p2password, on 1,923 cameras; the account reportedly survives password changes and, on most firmware, even factory resets, while offline-generated recovery codes could provide additional cloud-level administrative reset capability by serial number. Hunt.io said some CVE labels used in the tooling were incorrect, including a misreference to CVE-2024-39943 and an overbroad use of CVE-2025-31702, and it made no attribution claim for the campaign. The same host also staged a separate UPX-packed Windows payload believed to be SalatStealer and a PowerShell script for Microsoft Defender exclusions. Defenders were urged to treat exposed Dahua cameras as potentially compromised, remove the p2pwn account, rotate credentials, disable P2P where unnecessary, and apply firmware updates covered by Dahua SA-2021-0130.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.