SalatStealer is a Windows-focused Go-based malware-as-a-service infostealer that also incorporates substantial remote-access trojan functionality. It has been described under the NyashTeam or WebRAT branding and has been observed in criminal distribution ecosystems as well as in campaigns targeting Ukrainian entities. The malware is commonly packed or disguised to hinder analysis and uses encrypted configuration data, runtime decryption, and resilient command-and-control resolution mechanisms including DNS-over-HTTPS and, in newer samples, TON blockchain DNS. Command-and-control traffic has been observed over encrypted WebSocket channels with QUIC or HTTP/3 support, complicating network-based detection and sinkholing efforts.
Its core functionality centers on theft of browser credentials, cookies, session material, authentication tokens, wallet data, and other locally stored secrets. SalatStealer targets a broad set of Chromium- and Gecko-based browsers, numerous cryptocurrency wallets, messaging and gaming applications, and browser extensions associated with digital assets. Reported collection includes browser login databases, cookies, local state data, Firefox credential stores, Telegram Desktop data, Discord tokens, Steam-related data, clipboard contents, screenshots, and keylogged input. Multiple reports also describe theft of browser sessions and cryptocurrency wallet material, making it useful for account takeover and financial fraud.
Beyond infostealing, SalatStealer includes RAT capabilities such as arbitrary command execution, interactive shell access, screen capture, desktop recording, webcam capture, microphone capture, hidden desktop interaction, process control, file download, and SOCKS5 or peer-to-peer proxy functionality. It has been specifically associated with abuse of FFmpeg DirectShow interfaces for covert multimedia device discovery and active webcam capture on Windows systems. Additional reported capabilities include persistence, task scheduling, self-deletion, clipboard monitoring, privilege escalation, token theft, LSASS targeting, COM elevation abuse, and Microsoft Defender exclusion abuse.
Observed delivery vectors include phishing and spearphishing campaigns, malicious archives containing executables, links to compromised websites, ClickFix-style social engineering, fake meeting lures, cracked software, game cheats, and broader pay-per-install botnet distribution. SalatStealer has also been distributed by the Amadey botnet as part of a multi-family install marketplace alongside other commodity stealers and RATs. In Ukrainian-targeted activity tracked as UAC-0252, it was delivered through impersonation of government institutions and in some cases linked to exploitation of CVE-2025-8088 in WinRAR-themed intrusion chains.
Victim targeting is broad in criminal campaigns, but public reporting also ties SalatStealer to operations against Ukrainian government and related organizations. Its combination of credential theft, session hijacking, wallet theft, surveillance features, proxying, and post-compromise remote access makes it more capable than a typical commodity stealer and suitable for both financially motivated intrusion sets and hybrid espionage-crime operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAC-0252 Campaign (Jan--Feb 2026) SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252 ... Initial vector: CVE-2025-8088 (WinRAR path traversal) distributed via the PalachPro Telegram channel. | A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.
NyashTeam has been distributing SalatStealer through 15+ fake CVE proof-of-concept repositories on GitHub: ... github[.]com/DExplo1ted/CVE-2025-12596-Exploit
NyashTeam has been distributing SalatStealer through 15+ fake CVE proof-of-concept repositories on GitHub: ... github[.]com/h4xnz/CVE-2025-55234-POC
Campaign Context Distribution via Fake CVE PoCs (NyashTeam, Dec 2025 -- present) NyashTeam has been distributing SalatStealer through 15+ fake CVE proof-of-concept repositories on GitHub: github[.]com/RedFoxNxploits/CVE-2025-10294-Poc github[.]com/FixingPhantom/CVE-2025-10294
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group's arsenal includes an infostealer named SHADOWSNIFF, a Malware-as-a-Service (MaaS) variant called SALATSTEALER, and DEAFTICK, a Go-based backdoor strain.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
They either deliver a compressed archive containing a malicious executable file directly, or they provide a link to a compromised website.
On execution: mutex check ( checkDupe ), UAC bypass ( Elevate ), persistence via registry Run key and Task Scheduler...
the threat actor leverages PowerShell, BITSAdmin, and lightweight obfuscation techniques to stage and deploy SalatStealer
the threat actor leverages PowerShell, BITSAdmin, and lightweight obfuscation techniques to stage and deploy SalatStealer
Pour échapper à la détection, le malware utilise plusieurs techniques d’évasion, notamment la compression de son code et la détection des environnements d’analyse.
main.DuplicateUserTokenFromSessionID -- WTS token duplication main.getSystemToken -- SYSTEM token acquisition
main.NtQuerySystemHandles -- Handle enumeration (LSASS targeting) main.findLsassProcess -- LSASS process location
Il intègre également des fonctionnalités de surveillance, comme l’enregistrement des frappes clavier et la capture d’écran, lui permettant de récupérer davantage de données sensibles.
Collection hits 34 browsers, 28 crypto wallets, Telegram/Discord/Steam tokens, keylogger with window context, screenshots, and clipboard.
Son objectif principal est de voler des données sensibles sur les systèmes Windows, notamment les identifiants de connexion, les cookies de navigation, les informations enregistrées dans les navigateurs et les données associées aux portefeuilles de cryptomonnaies.
MITRE ATT&CK Mapping Technique ID Implementation Credentials in Files T1552.001 Browser profile data, wallet files
Son objectif principal est de voler des données sensibles sur les systèmes Windows, notamment les identifiants de connexion, les cookies de navigation, les informations enregistrées dans les navigateurs et les données associées aux portefeuilles de cryptomonnaies.
En plus du vol d’informations, SalatStealer collecte des renseignements sur le système compromis, tels que la configuration de la machine, les logiciels installés et les informations utilisateur.
Son objectif principal est de voler des données sensibles sur les systèmes Windows, notamment les identifiants de connexion, les cookies de navigation, les informations enregistrées dans les navigateurs et les données associées aux portefeuilles de cryptomonnaies.
Il intègre également des fonctionnalités de surveillance, comme l’enregistrement des frappes clavier et la capture d’écran, lui permettant de récupérer davantage de données sensibles.
Il intègre également des fonctionnalités de surveillance, comme l’enregistrement des frappes clavier et la capture d’écran, lui permettant de récupérer davantage de données sensibles.
The transport layer uses gorilla/websocket over HTTPS with QUIC/HTTP3 support (via quic-go). The C2 path is /saat/ with a WebSocket session protocol ( wsSess ) for bidirectional command execution.
Every infected host becomes a SOCKS5 proxy node: main.(*socks5Conn).Serve -- SOCKS5 server ... main.p2pSocks -- P2P SOCKS relay
The actual C2 connection uses WebSocket over TLS for command-and-control, and QUIC (HTTP/3) for bulk data exfiltration.
the threat actor leverages PowerShell, BITSAdmin, and lightweight obfuscation techniques to stage and deploy SalatStealer
A tloop function implements a polling loop that periodically re-resolves via TON, meaning the operator can rotate infrastructure mid-campaign and all infected hosts will follow within one polling interval. This is Fast Flux DNS with the blockchain as the authoritative server.
104 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware label applied in public threat intelligence to a hash linked to Tengu activity; the content suggests possible multi-use tooling or classification ambiguity rather than a clearly established separate role.
An information-stealing malware delivered via a ClickFix-style social engineering campaign that abuses legitimate Windows tools such as PowerShell and BITSAdmin. It targets browser data and cryptocurrency wallets to enable credential theft, session hijacking, and digital asset compromise.
A stealer malware family described as abusing FFmpeg on Windows to enumerate connected audio and video devices, likely as reconnaissance for covert audio/video surveillance or collection.
A stealer malware family associated here with webcam/video capture activity via FFmpeg and Windows DirectShow as part of collection and surveillance behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.