Skip to main content
Mallory
🇷🇺 RU2 malware families

NyashTeam

Also known asNyashTeam

NyashTeam is a Russian-speaking malware-as-a-service (MaaS) operator active since approximately 2022. The group is associated with the NyashTeam / WebRat brand and is described as selling remote access trojans and stealer malware, including WebRAT (also referred to in reporting as SalatStealer) and DCRat (DarkCrystal RAT), via Telegram bots and websites. Reporting also describes NyashTeam as offering custom-made malware and server hosting to Russian-speaking cybercriminals. NyashTeam is linked to the operation and sale of SalatStealer/WebRAT, a Go-based malware family that combines RAT and infostealer functionality. Reported capabilities include theft of browser credentials and cookies, cryptocurrency wallet data, Telegram Desktop data, Discord tokens, Steam data, clipboard monitoring, keylogging, screen/webcam/microphone capture, remote shell access, SOCKS5 proxying, persistence, task scheduling, privilege escalation, and LSASS targeting. SalatStealer/WebRAT has been reported to use encrypted configuration, DNS-over-HTTPS and TON DNS-based C2 resolution, and WebSocket over TLS with QUIC/HTTP3 for exfiltration. The group’s operator portal was reported at nyash[.]team, advertising itself as the "OFFICIAL WebRat reseller." Sales and support were conducted through Telegram bots including @nyash_team_bot and @nyashsupbot. Infrastructure linked in reporting includes domains such as nyash[.]team, webrat[.]ru, webrat[.]top, wrat[.]in, salat[.]cn, and sa1at[.]ru, with Russian-hosted infrastructure in Moscow, Rostov-na-Donu, and Saint Petersburg also described. CERT-F6/F6 reportedly disrupted more than 110 NyashTeam domains in July 2025, but subsequent reporting states the group rebuilt infrastructure within months. Known aliases and associated branding directly mentioned in the content include WebRat and NyashTeam / WebRat.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Academia & Research

Where they target

Geographies tied to known operations.

  • 🇺🇦 Ukraine

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

10 of 15 tactics63 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
TA0003
Persistence
3 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1112
Modify Registry
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
5 techniques
T1053
Scheduled Task/Job
T1053.005×2
Scheduled Task
T1055
Process Injection
T1134×2
Access Token Manipulation
T1134.001
Token Impersonation/Theft
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
T1548
Abuse Elevation Control Mechanism
T1548.002
Bypass User Account Control
TA0005
Stealth
5 techniques
T1027
Obfuscated Files or Information
T1027.002
Software Packing
T1055
Process Injection
T1070
Indicator Removal
T1070.004
File Deletion
T1134×2
Access Token Manipulation
T1134.001
Token Impersonation/Theft
T1497
Virtualization/Sandbox Evasion
TA0112
Defense Impairment
1 technique
T1112
Modify Registry
TA0006
Credential Access
6 techniques
T1003
OS Credential Dumping
T1003.001×2
LSASS Memory
T1056
Input Capture
T1056.001×2
Keylogging
T1528
Steal Application Access Token
T1539
Steal Web Session Cookie
T1552
Unsecured Credentials
T1552.001
Credentials In Files
T1555
Credentials from Password Stores
T1555.001
Keychain
T1555.003×2
Credentials from Web Browsers
TA0007
Discovery
6 techniques
T1012
Query Registry
T1057
Process Discovery
T1082×2
System Information Discovery
T1217
Browser Information Discovery
T1497
Virtualization/Sandbox Evasion
T1614
System Location Discovery
T1614.001
System Language Discovery
TA0009
Collection
6 techniques
T1005
Data from Local System
T1056
Input Capture
T1056.001×2
Keylogging
T1113×2
Screen Capture
T1115×2
Clipboard Data
T1123×2
Audio Capture
T1125×2
Video Capture
TA0011
Command and Control
6 techniques
T1071
Application Layer Protocol
T1071.001×2
Web Protocols
T1090
Proxy
T1090.003×2
Multi-hop Proxy
T1095
Non-Application Layer Protocol
T1219
Remote Access Tools
T1568
Dynamic Resolution
T1568.001
Fast Flux DNS
T1573
Encrypted Channel
T1573.002
Asymmetric Cryptography
TA0010
Exfiltration
1 technique
T1041
Exfiltration Over C2 Channel
IOCS

Observables

33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

breakglass intelNews
Mar 15, 2026
SalatStealer's New Trick: Using TON Blockchain DNS to Make C2 Takedowns Impossible - Breakglass Intelligence - Breakglass Intelligence

Russian-speaking malware-as-a-service group operating and distributing SalatStealer/WebRAT, selling access since approximately 2022, rebuilding infrastructure after prior disruption, and using TON blockchain DNS for resilient C2. The group also distributes DCRat and has used fake CVE PoC GitHub repositories and Telegram channels for delivery.

Read more
breakglass intelNews
Mar 5, 2026
Salat Stealer: Go-Compiled RAT with DNS-over-HTTPS C2 Resolution, 62 Crypto Wallet Extensions, and a Live MaaS Panel on Russian Infrastructure - Breakglass Intelligence - Breakglass Intelligence

Operating a malware-as-a-service platform tied to SalatStealer, with reseller infrastructure, affiliate routing, Cloudflare-fronted exfiltration domains, Beget-hosted backends, and Telegram-based sales/support.

Read more
the hacker newsNews
Dec 25, 2025
ThreatsDay Bulletin: Stealth Loaders, AI Chatbot Flaws AI Exploits, Docker Hack, and 15 More Stories

NyashTeam is a cybercriminal group selling WebRAT and DCRat, malware used for remote access, data theft, and spyware functions, often distributed via fake PoC exploits.

Read more
the hacker newsNews
Sep 15, 2025
⚡ Weekly Recap: Bootkit Malware, AI-Powered Attacks, Supply Chain Breaches, Zero-Days & More

NyashTeam is a Russian-speaking cybercriminal group offering Salat Stealer (aka WEB_RAT or WebRAT) as malware-as-a-service, targeting browser credentials and cryptocurrency wallets.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping39

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables33

Domains, IPs, and hashes tied to this actor, refreshed continuously.