Skip to content

SALATSTEALER

SalatStealer, also marketed as WebRAT, is a Windows-focused Go-based malware family combining extensive information-stealing functionality with remote-access-trojan capabilities.

Profile source: Mallory opens in a new tab

SALATSTEALER

Family profile

SalatStealer, also marketed as WebRAT, is a Windows-focused Go-based malware family combining extensive information-stealing functionality with remote-access-trojan capabilities. It is associated with the Russian-speaking NyashTeam malware-as-a-service operation and has been distributed through phishing lures, ClickFix social engineering, compromised websites, malicious archives, pirated software, gaming cheats, and pay-per-install campaigns including Amadey activity. The malware targets browser credentials, cookies, session data, authentication tokens, cryptocurrency wallets and browser extensions, messaging-application data, gaming-platform tokens, clipboard contents, and system information. It can bypass Chromium App-Bound Encryption to recover protected browser data. SalatStealer supports remote command execution, reverse-shell access, file operations, screen, webcam, microphone, and desktop capture, keylogging, hidden-desktop interaction, SOCKS5 proxying, process control, privilege-related token operations, and LSASS targeting. It can establish persistence and impair Microsoft Defender protections. Recent variants resolve command-and-control infrastructure dynamically through TON blockchain DNS, with DNS-over-HTTPS fallback, and use encrypted WebSocket communications and QUIC-capable data transfer to complicate network-based disruption and detection.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 2, 2026
Feed role
C2 / Distribution
Host form
101 IP / 60 hostnames

Leading locations

  • US33
  • DE23
  • CN22
  • NL16
  • HK10
  • RU10
  • KR7
  • GB5
  • LU5
  • SG5
  • TH3
  • FR2

Leading providers

  • Cloudflare, Inc.8
  • Omegatech LTD8
  • CTG Server Limited7
  • FEMO IT SOLUTIONS LIMITED7
  • HostPapa7
  • Ghosty Networks LLC5

Infrastructure traits

  • Hosting 129
  • Anycast 8

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
UAC-0252

The group's arsenal includes an infostealer named SHADOWSNIFF, a Malware-as-a-Service (MaaS) variant called SALATSTEALER, and DEAFTICK, a Go-based backdoor strain.

Handala

This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.

FIN7

This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.

NyashTeam

A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.

Exploited software

Vulnerabilities linked to SALATSTEALER

4 CVEs

MITRE ATT&CK

SALATSTEALER in ATT&CK

56 distinct techniques

Techniques

56 techniques
T1562 Impair Defenses T1562.001 Disable or Modify Tools T1113 Screen Capture T1553.004 Install Root Certificate T1112 Modify Registry T1027.002 Software Packing T1614.001 System Language Discovery T1059.001 PowerShell T1102 Web Service T1568 Dynamic Resolution T1056.001 Keylogging T1027 Obfuscated Files or Information T1566 Phishing T1539 Steal Web Session Cookie T1555 Credentials from Password Stores T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1497 Virtualization/Sandbox Evasion T1082 System Information Discovery T1584 Compromise Infrastructure T1204.002 Malicious File T1189 Drive-by Compromise T1125 Video Capture T1197 BITS Jobs T1204 User Execution T1105 Ingress Tool Transfer T1003.001 LSASS Memory T1123 Audio Capture T1071.001 Web Protocols T1053.005 Scheduled Task T1552.001 Credentials In Files T1573.002 Asymmetric Cryptography T1090.003 Multi-hop Proxy T1528 Steal Application Access Token T1614 System Location Discovery T1568.001 Fast Flux DNS T1115 Clipboard Data T1134 Access Token Manipulation T1566.002 Spearphishing Link T1095 Non-Application Layer Protocol T1070.004 File Deletion T1547.001 Registry Run Keys / Startup Folder T1055 Process Injection T1134.001 Token Impersonation/Theft T1555.003 Credentials from Web Browsers T1555.001 Keychain T1057 Process Discovery T1548.002 Bypass User Account Control T1012 Query Registry T1219 Remote Access Tools T1573 Encrypted Channel T1217 Browser Information Discovery T1071 Application Layer Protocol T1203 Exploitation for Client Execution T1036 Masquerading T1566.001 Spearphishing Attachment

Reporting

Research mentioning SALATSTEALER

Aug 18
Reddit Netsec

πŸŽ₯ Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia : r/netsec

Researchers reconstructed Operation CameraSwarm, a 35-day campaign that compromised more than 14,530 Dahua IP cameras, with the largest concentration of affected devices in Ukraine and Russia. The operation was pieced together from an exposed directory on 154.86.119.60 containing the operator’s tooling, logs, source code, and staging files. According to the report, the attackers used three parallel access paths: credential brute forcing on TCP/37777, exploitation of CVE-2021-33044 and CVE-2021-33045, and abuse of Dahua’s P2P cloud relay to reach cameras by serial number. Researchers said the relay path relied on cloud-issued session tokens obtainable through fixed SDK credentials embedded in Dahua clients, enabling unauthenticated access through that channel. The operators also installed a persistent backdoor account, p2pwn / p2password, on 1,923 cameras; the account reportedly survives password changes and, on most firmware, even factory resets, while offline-generated recovery codes could provide additional cloud-level administrative reset capability by serial number. Hunt.io said some CVE labels used in the tooling were incorrect, including a misreference to CVE-2024-39943 and an overbroad use of CVE-2025-31702, and it made no attribution claim for the campaign. The same host also staged a separate UPX-packed Windows payload believed to be SalatStealer and a PowerShell script for Microsoft Defender exclusions. Defenders were urged to treat exposed Dahua cameras as potentially compromised, remove the p2pwn account, rotate credentials, disable P2P where unnecessary, and apply firmware updates covered by Dahua SA-2021-0130.

Aug 18
Huntio

Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.