Salat Stealer is a Windows-based, Go-written information stealer also referred to as WEB_RAT/WebRAT. It is described as a malware-as-a-service offering operated by a Russian-speaking group identified as NyashTeam, and it has also been associated with UAC-0252 activity, which has delivered it alongside the ShadowSniff credential harvester. The malware performs host reconnaissance, including profiling hardware, active processes, and environmental attributes. Its theft capabilities include browser-saved passwords, cookies, autofill data, and session tokens from Chromium- and Gecko-based browsers, as well as credentials and cryptocurrency wallet data. Beyond standard infostealer behavior, reported capabilities include local file exfiltration, live desktop streaming, and webcam and microphone monitoring, effectively turning infected hosts into surveillance endpoints. Reported delivery vectors include phishing emails, trojanized software packages or installers, social-engineering lures, and bundled gaming utilities such as Xeno Executor; RuTube videos advertising Roblox cheats have also been cited as lures leading to Salat Stealer infections. The malware is described as operating from user-context directories to reduce visibility, compressing stolen data, and exfiltrating it to attacker-controlled command-and-control infrastructure, often over encrypted channels. It has also been reported to tamper with Microsoft Defender via PowerShell Set-MpPreference commands that set high-, moderate-, low-, and severe-threat default actions to allow, aiding defense evasion. Reported targeting includes organizations in Ukraine and surrounding regions. High-confidence indicators mentioned in the content include the domain xenoexecutor.in and the SHA-256 hashes 60118ba6124480d1c28b3d30f380aa64030418ba1774e8437f9cfae5ea191271, 075b3caa3a754c23f929a1591c6b333c7da1080a5fdf8ea2a3497d1505b60dde, 7376aaca33eab974ec527d44753d8016c1d305e2db935189a91a57b0ecbb3ccd, fec793499d9df0458b611a71dda23b41ba1c28038a79924ab606937e26e77115, 7018dc48efdf1311d644225e3c9e5f8f6d49863dbaca315f16d25473f127978d, and 347e3ef094831fd280628c711804603f695b020e365606174a6ba118ebf56cff.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Salat Stealer is a Windows-based information-stealing malware associated with the UAC-0252 threat activity group, which has been observed delivering it alongside the ShadowSniff credential harvester.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware also exfiltrates local files, turning infected hosts into real-time surveillance points.
Moving beyond standard theft, it enables live desktop streaming and webcam/microphone monitoring.
Moving beyond standard theft, it enables live desktop streaming and webcam/microphone monitoring.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Go-based infostealer that performs host reconnaissance, steals data, exfiltrates local files, and supports live desktop streaming plus webcam/microphone surveillance. The content says it is often distributed via social engineering and bundled with gaming utilities like Xeno Executor to steal credentials and wallets.
A named stealer malware referenced in an attack simulation dataset involving ffmpeg activity.
Windows-based information stealer that harvests browser-saved passwords, cookies, autofill data, and session tokens from Chromium- and Gecko-based browsers. It also tampers with Windows Defender via PowerShell Set-MpPreference commands to weaken defenses, persists in user-context directories, and exfiltrates collected data to attacker-controlled C2 infrastructure.
Referenced as malware associated with this detection; the content does not provide behavioral detail beyond indicating it is a stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.