WebRAT, also known as Salat Stealer, is a Windows-focused remote access trojan with information-stealing and surveillance functionality first observed in early 2025. It provides attackers with remote control of compromised systems and steals data associated with cryptocurrency wallets and Telegram, Discord, and Steam accounts. Supported surveillance features include keylogging, screen recording, and webcam and microphone capture.
WebRAT was initially distributed through game cheats and cracked software, including lures themed around popular games. From at least September 2025, its operators also used fake GitHub proof-of-concept repositories targeting students, junior security researchers, and other users seeking exploit code. These repositories used detailed, apparently machine-generated vulnerability documentation and password-protected archives to make malicious downloads appear credible. A Windows loader in this delivery chain attempts privilege escalation, disables Microsoft Defender, and retrieves the WebRAT payload.
The family is associated with financially motivated, opportunistic activity; no reliable attribution to a named threat actor is established. The observed campaigns create risk for corporate and research environments when untrusted exploit code, pirated software, or gaming utilities are executed outside isolated analysis environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
On execution: mutex check ( checkDupe ), UAC bypass ( Elevate ), persistence via registry Run key and Task Scheduler...
main.DuplicateUserTokenFromSessionID -- WTS token duplication main.getSystemToken -- SYSTEM token acquisition
main.DuplicateUserTokenFromSessionID -- WTS token duplication main.getSystemToken -- SYSTEM token acquisition
The PE sections are labeled UPX0 , UPX1 , UPX2 . But run upx -d and you get NotPackedException: not packed by UPX . The section names are fake -- a social engineering artifact targeting analysts...
“malicious HWP file disguised as a… document” and “abusing the icon of SentinelOne… spoofing it… Rust based implant… acting as a legitimate binary” and “Webrat… disguising itself as cheats… or as cracked software.”
main.NtQuerySystemHandles -- Handle enumeration (LSASS targeting) main.findLsassProcess -- LSASS process location
main.runKeylogger -- Start capture main.keyPressCallback -- SetWindowsHookEx WH_KEYBOARD callback main.windowChangeCallback -- Active window change (context labeling)
Collection hits 34 browsers, 28 crypto wallets, Telegram/Discord/Steam tokens, keylogger with window context, screenshots, and clipboard.
Chromium-based browsers get the full treatment: DPAPI master key decryption, AES-GCM cookie/password decryption...
main.runKeylogger -- Start capture main.keyPressCallback -- SetWindowsHookEx WH_KEYBOARD callback main.windowChangeCallback -- Active window change (context labeling)
The actual C2 connection uses WebSocket over TLS for command-and-control, and QUIC (HTTP/3) for bulk data exfiltration.
Every infected host becomes a SOCKS5 proxy node: main.(*socks5Conn).Serve -- SOCKS5 server ... main.p2pSocks -- P2P SOCKS relay
The actual C2 connection uses WebSocket over TLS for command-and-control, and QUIC (HTTP/3) for bulk data exfiltration.
SalatStealer is not just a stealer -- it is a full RAT ... screen streaming, shell, SOCKS proxy
SalatStealer has been documented before ... The binary imports github.com/xssnick/tonutils-go v1.16.0 and implements two functions: main.tonResolve and main.tryTonResolve.
A tloop function implements a polling loop that periodically re-resolves via TON, meaning the operator can rotate infrastructure mid-campaign and all infected hosts will follow within one polling interval. This is Fast Flux DNS with the blockchain as the authoritative server.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojan/RAT delivered through fake CVE proof-of-concept repositories in a separate late-2025 campaign targeting researchers-in-training such as students and junior testers.
Referenced as malware similar to CrystalRAT; also known as Salat Stealer.
A previously known malware/tool written in Go whose panel layout and sales infrastructure closely resembled early Webcrystal RAT, suggesting CrystalX evolved from or was heavily inspired by it.
Previously known malware whose panel and sales workflow closely resembled CrystalX RAT/Webcrystal RAT; referenced as a likely template or predecessor and also known as Salat Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.