Salat Stealer, also known as WEB_RAT or WebRAT, is a Go-based information stealer targeting Windows systems. Identified in August 2025, it is commercialized as malware-as-a-service by Russian-speaking actors associated with NyashTeam and Kapchenka. It has also been deployed by the UAC-0252 threat activity group alongside the ShadowSniff credential harvester in campaigns targeting organizations in Ukraine and surrounding regions.
The malware harvests browser-stored passwords, cookies, autofill information, and session tokens, as well as Telegram and Steam session data. It targets desktop cryptocurrency wallets and browser wallet extensions to obtain wallet data, private keys, and seed material. It profiles infected systems by collecting hardware details, running processes, and environmental information, and exfiltrates collected data and local files to attacker-controlled infrastructure. Additional capabilities include live desktop streaming, webcam and microphone monitoring, and remote execution of custom PowerShell scripts through a web-based management panel.
Salat Stealer uses UPX packing, process masquerading, hidden windows, and Windows Defender configuration tampering to evade detection. It establishes persistence through registry Run entries and scheduled tasks. Its management infrastructure supports encrypted communications, fallback destinations, payload building, script management, and sharing access to compromised systems. Distribution includes phishing messages, trojanized software installers, and social-engineering lures advertising gaming utilities, cheats, cracks, and bots through video-sharing platforms, file-sharing archives, and abused repositories.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks.
CYFIRMA has identified Salat Stealer (also known as WEB_RAT), a sophisticated Go-based infostealer targeting Windows systems. The malware exfiltrates browser credentials, cryptocurrency wallet data, and session information while employing advanced evasion techniques, including UPX packing, process masquerading, registry run keys, and scheduled tasks.
Salat Stealer is a Windows-based information-stealing malware associated with the UAC-0252 threat activity group, which has been observed delivering it alongside the ShadowSniff credential harvester.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware also exfiltrates local files, turning infected hosts into real-time surveillance points.
Moving beyond standard theft, it enables live desktop streaming and webcam/microphone monitoring.
Moving beyond standard theft, it enables live desktop streaming and webcam/microphone monitoring.
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based infostealer that performs host reconnaissance, steals data, exfiltrates local files, and supports live desktop streaming plus webcam/microphone surveillance. The content says it is often distributed via social engineering and bundled with gaming utilities like Xeno Executor to steal credentials and wallets.
A named stealer malware referenced in an attack simulation dataset involving ffmpeg activity.
Windows-based information stealer that harvests browser-saved passwords, cookies, autofill data, and session tokens from Chromium- and Gecko-based browsers. It also tampers with Windows Defender via PowerShell Set-MpPreference commands to weaken defenses, persists in user-context directories, and exfiltrates collected data to attacker-controlled C2 infrastructure.
Referenced as malware associated with this detection; the content does not provide behavioral detail beyond indicating it is a stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.