Skip to content

Webrat

WebRAT, also referred to as Salat Stealer, is a backdoor/remote access trojan with information-stealing and spyware capabilities that was first reported in early 2025.

Profile source: Mallory opens in a new tab

Webrat

Family profile

WebRAT, also referred to as Salat Stealer, is a backdoor/remote access trojan with information-stealing and spyware capabilities that was first reported in early 2025. It allows attackers to control infected Windows systems and steal data from cryptocurrency wallets and from Telegram, Discord, and Steam accounts. Reported surveillance functions include keylogging, screen recording or screenshot capture, and webcam and microphone monitoring. Multiple reports describe it as a backdoor with credential theft and device surveillance functionality, and some reporting also characterizes it as an infostealer.

Observed distribution initially included pirated software, cracked applications, and game cheats for titles such as Roblox, Counter-Strike, Rust, and gaming utilities. By at least September 2025, operators expanded distribution to fake GitHub repositories masquerading as proof-of-concept exploit code for recently disclosed or high-profile CVEs, specifically targeting students, junior testers, infosec enthusiasts, and less-experienced security researchers. The repositories used detailed, often machine-generated descriptions to appear legitimate and typically delivered password-protected ZIP archives. These archives contained a decoy DLL, a batch file, and a loader executable such as rasmanesc.exe.

The documented loader behavior includes privilege escalation, disabling Microsoft Defender, and downloading the main WebRAT payload from hardcoded infrastructure. Reported infrastructure and IOCs include the domains ezc5510min.temp.swtest.ru and shopsleta.ru, and MD5 hashes including 61b1fc6ab327e6d3ff5fd3e82b430315, 28a741e9fcd57bd607255d3a4690c82f, and a13c3d863e8e2bd7596bac5d41581f6a. Kaspersky reported identifying 15 malicious GitHub repositories used in one such campaign. The campaign’s novelty was the social-engineering lure rather than major functional changes in the malware.

WebRAT is also notable as a reference point for later malware families. Kaspersky reported that CrystalRAT/CrystalX RAT shares strong similarities with WebRAT/Salat Stealer, including similar panel design, Go-based code, and a similar bot-based sales system. Separate reporting also noted WebRAT appearing as a payload delivered by Olymp Loader in 2025.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 10, 2026
Last activity
Sep 10, 2026
Feed role
C2
Host form
7 IP / 15 hostnames

Leading locations

  • US7
  • DE3
  • FI2
  • RU2
  • NL1

Leading providers

  • Cloudflare, Inc.7
  • Scalaxy B.V.3
  • Citytelecom LLC1
  • Inios Oy1
  • LLC Digital Network1
  • TechTies Inc.1

Infrastructure traits

  • Hosting 15
  • Anycast 7

Samples

Recent associated samples

MITRE ATT&CK

Webrat in ATT&CK

30 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.