Skip to content

SALATSTEALER

SalatStealer is a Windows-focused Go-based malware-as-a-service infostealer that also incorporates substantial remote-access functionality.

Profile source: Mallory opens in a new tab

SALATSTEALER

Family profile

SalatStealer is a Windows-focused Go-based malware-as-a-service infostealer that also incorporates substantial remote-access functionality. It has been described under the NyashTeam or WebRAT branding and has been observed in criminal distribution ecosystems as well as in targeted campaigns against Ukrainian entities. The malware is commonly packed or disguised to hinder analysis and uses encrypted configuration data, runtime decryption, and resilient command-and-control resolution mechanisms including DNS-over-HTTPS and, in newer variants, TON blockchain DNS. Communications have been observed over WebSocket secured with TLS, with QUIC or HTTP/3 support used for bulk data transfer.

Its core purpose is theft of high-value user data. SalatStealer targets credentials, cookies, browser databases, local state material, authentication tokens, and cryptocurrency wallet data from a wide range of Chromium- and Gecko-based browsers. It also targets browser extensions associated with digital-asset wallets, extracts data from messaging and gaming applications, and can collect clipboard contents relevant to cryptocurrency theft. Reported collection includes browser logins, session material, wallet artifacts, Telegram and Discord data, Steam-related data, screenshots, and other host-resident information suitable for account takeover and financial fraud.

Beyond classic infostealer behavior, SalatStealer includes RAT capabilities such as arbitrary command execution, interactive shell access, screen capture, desktop recording, webcam capture, microphone capture, keylogging, file download, process control, hidden desktop interaction, and SOCKS5 or peer-to-peer proxy functionality. These features enable both surveillance and broader post-compromise utility. Observed abuse of FFmpeg through the Windows DirectShow interface indicates support for covert multimedia device discovery and active video capture on infected hosts.

The malware employs multiple defensive and privilege-related techniques. Reported behaviors include adding Microsoft Defender exclusions, persistence through autorun mechanisms and scheduled tasks, COM-based elevation abuse to bypass browser protections, token manipulation, LSASS targeting, and anti-analysis measures such as misleading packer artifacts and runtime-obfuscated configuration. It has also been associated with process injection or hollowing in broader delivery chains and with self-deletion or cleanup behaviors.

Observed delivery has been diverse and strongly aligned with commodity cybercrime tradecraft. SalatStealer has been distributed via cracked software, game cheats, phishing and spearphishing campaigns, ClickFix-style lures, malicious archives containing executables or shortcuts, compromised websites, fake meeting-themed landing pages, and pay-per-install botnet ecosystems such as Amadey. It has also been linked to campaigns abusing GitHub-hosted payloads and to exploitation of CVE-2025-8088 in attacks impersonating Ukrainian government institutions.

Victim targeting spans broad criminal monetization as well as regionally focused operations. SalatStealer has been observed in campaigns targeting Ukrainian government institutions and Ukrainian-speaking organizations, while commodity distribution activity indicates wider global targeting of consumers and enterprises for credential theft, session hijacking, and cryptocurrency compromise. Its combination of infostealing, surveillance, and remote-access features makes it useful both as a standalone theft platform and as an enabling tool within larger intrusion chains.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Reconnaissance
  • Session Hijacking
  • Spoofing

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
37 IP / 17 hostnames

Leading locations

  • DE9
  • US9
  • NL8
  • CN6
  • RU6
  • KR3
  • LU3
  • PL2
  • BR1
  • CA1
  • FR1
  • IE1

Leading providers

  • Omegatech LTD4
  • DEDIK SERVICES LIMITED3
  • DigitalOcean, LLC3
  • Ghosty Networks LLC3
  • Beget LLC2
  • HosterDaddy Private Limited2

Infrastructure traits

  • Hosting 47
  • Vpn 2
  • Anycast 1

Samples

Recent associated samples

Reported operators

Threat actors

4 named in public reporting
UAC-0252

The group's arsenal includes an infostealer named SHADOWSNIFF, a Malware-as-a-Service (MaaS) variant called SALATSTEALER, and DEAFTICK, a Go-based backdoor strain.

Handala

This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.

FIN7

This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.

NyashTeam

A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.

Exploited software

Vulnerabilities linked to SALATSTEALER

4 CVEs

MITRE ATT&CK

SALATSTEALER in ATT&CK

53 distinct techniques

Techniques

53 techniques
T1056.001 Keylogging T1027 Obfuscated Files or Information T1566 Phishing T1539 Steal Web Session Cookie T1555 Credentials from Password Stores T1113 Screen Capture T1005 Data from Local System T1041 Exfiltration Over C2 Channel T1497 Virtualization/Sandbox Evasion T1082 System Information Discovery T1584 Compromise Infrastructure T1204.002 Malicious File T1189 Drive-by Compromise T1125 Video Capture T1562 Impair Defenses T1197 BITS Jobs T1204 User Execution T1105 Ingress Tool Transfer T1059.001 PowerShell T1003.001 LSASS Memory T1123 Audio Capture T1071.001 Web Protocols T1053.005 Scheduled Task T1552.001 Credentials In Files T1573.002 Asymmetric Cryptography T1090.003 Multi-hop Proxy T1528 Steal Application Access Token T1614 System Location Discovery T1568.001 Fast Flux DNS T1115 Clipboard Data T1134 Access Token Manipulation T1566.002 Spearphishing Link T1095 Non-Application Layer Protocol T1070.004 File Deletion T1547.001 Registry Run Keys / Startup Folder T1055 Process Injection T1134.001 Token Impersonation/Theft T1112 Modify Registry T1555.003 Credentials from Web Browsers T1555.001 Keychain T1614.001 System Language Discovery T1057 Process Discovery T1568 Dynamic Resolution T1548.002 Bypass User Account Control T1012 Query Registry T1219 Remote Access Tools T1027.002 Software Packing T1573 Encrypted Channel T1217 Browser Information Discovery T1071 Application Layer Protocol T1203 Exploitation for Client Execution T1036 Masquerading T1566.001 Spearphishing Attachment

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.