Last seven days
- First activity
- Sep 10, 2026
- Last activity
- Sep 10, 2026
- Feed role
- C2
- Host form
- 7 IP / 15 hostnames
WebRAT, also referred to as Salat Stealer, is a backdoor/remote access trojan with information-stealing and spyware capabilities that was first reported in early 2025.
Profile source: Mallory opens in a new tabWebrat
WebRAT, also referred to as Salat Stealer, is a backdoor/remote access trojan with information-stealing and spyware capabilities that was first reported in early 2025. It allows attackers to control infected Windows systems and steal data from cryptocurrency wallets and from Telegram, Discord, and Steam accounts. Reported surveillance functions include keylogging, screen recording or screenshot capture, and webcam and microphone monitoring. Multiple reports describe it as a backdoor with credential theft and device surveillance functionality, and some reporting also characterizes it as an infostealer.
Observed distribution initially included pirated software, cracked applications, and game cheats for titles such as Roblox, Counter-Strike, Rust, and gaming utilities. By at least September 2025, operators expanded distribution to fake GitHub repositories masquerading as proof-of-concept exploit code for recently disclosed or high-profile CVEs, specifically targeting students, junior testers, infosec enthusiasts, and less-experienced security researchers. The repositories used detailed, often machine-generated descriptions to appear legitimate and typically delivered password-protected ZIP archives. These archives contained a decoy DLL, a batch file, and a loader executable such as rasmanesc.exe.
The documented loader behavior includes privilege escalation, disabling Microsoft Defender, and downloading the main WebRAT payload from hardcoded infrastructure. Reported infrastructure and IOCs include the domains ezc5510min.temp.swtest.ru and shopsleta.ru, and MD5 hashes including 61b1fc6ab327e6d3ff5fd3e82b430315, 28a741e9fcd57bd607255d3a4690c82f, and a13c3d863e8e2bd7596bac5d41581f6a. Kaspersky reported identifying 15 malicious GitHub repositories used in one such campaign. The campaign’s novelty was the social-engineering lure rather than major functional changes in the malware.
WebRAT is also notable as a reference point for later malware families. Kaspersky reported that CrystalRAT/CrystalX RAT shares strong similarities with WebRAT/Salat Stealer, including similar panel design, Go-based code, and a similar bot-based sales system. Separate reporting also noted WebRAT appearing as a payload delivered by Olymp Loader in 2025.
C2 tracking
Derp observations, rolling seven-day window
Samples
238557bb7b62c8f7bf01bdd634b0ef688ff24c4e463e0de2f13ab8b054f4df6d 2a3beb2819a81dee6a301d5473c369f98d372c9dd33570e341a229535ad5b0ff 5601e9f5e3524dbca856001514e9e5a8116ad60917ebdc8dc9c01f2fb356b81b 5f05bb15be2babe22075ef2757cb9804901545e0fccc8a4df1224babef716bf2 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.