SalatStealer is a Windows-focused, UPX-packed Go malware family combining information-stealing and remote-access functionality. It is associated with a malware-as-a-service operation variously branded NyashTeam and WebRat and has been distributed through phishing, ClickFix social-engineering lures, compromised websites, pirated software, and game-cheat-themed lures. It has also appeared as a payload in Amadey-associated pay-per-install distribution activity and in UAC-0252 activity impersonating Ukrainian government entities.
The malware steals browser credentials, cookies, authentication tokens, browsing data, and Firefox-derived secrets; this supports credential theft and browser-session hijacking. It targets cryptocurrency wallet applications and browser extensions, messaging application data, Discord tokens, Steam data, and clipboard content. SalatStealer can bypass Chromium App-Bound Encryption through COM elevation abuse and can access browser secrets protected by DPAPI and Gecko NSS mechanisms.
SalatStealer provides remote shell access, file transfer, process control, SOCKS5 proxying, screen capture, desktop recording, webcam and microphone capture, and keylogging. It can use FFmpeg's DirectShow interface to enumerate multimedia devices and perform video capture. It includes persistence, privilege-adjustment, token-theft, LSASS-targeting, and Microsoft Defender exclusion capabilities, together with encrypted configuration data and anti-analysis measures. Command-and-control resolution has used DNS-over-HTTPS and, in some samples, TON smart-contract domain resolution; communications can use encrypted WebSocket/HTTPS channels with QUIC support.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
UAC-0252 Campaign (Jan--Feb 2026) SalatStealer was deployed alongside three other tools in a campaign targeting Ukraine, tracked as UAC-0252 ... Initial vector: CVE-2025-8088 (WinRAR path traversal) distributed via the PalachPro Telegram channel. | A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.
NyashTeam has been distributing SalatStealer through 15+ fake CVE proof-of-concept repositories on GitHub: ... github[.]com/DExplo1ted/CVE-2025-12596-Exploit
NyashTeam has been distributing SalatStealer through 15+ fake CVE proof-of-concept repositories on GitHub: ... github[.]com/h4xnz/CVE-2025-55234-POC
Campaign Context Distribution via Fake CVE PoCs (NyashTeam, Dec 2025 -- present) NyashTeam has been distributing SalatStealer through 15+ fake CVE proof-of-concept repositories on GitHub: github[.]com/RedFoxNxploits/CVE-2025-10294-Poc github[.]com/FixingPhantom/CVE-2025-10294
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group's arsenal includes an infostealer named SHADOWSNIFF, a Malware-as-a-Service (MaaS) variant called SALATSTEALER, and DEAFTICK, a Go-based backdoor strain.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
This analytic detects active video capture performed by FFmpeg (ffmpeg.exe) via the Windows DirectShow (dshow) interface, a technique observed in SalatStealer and related UAC-0252 campaigns.
A fresh SalatStealer sample ( yesamsevo.exe ) ships with a previously undocumented capability: resolving its C2 server address via TON blockchain DNS using tonutils-go.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
On execution: mutex check ( checkDupe ), UAC bypass ( Elevate ), persistence via registry Run key and Task Scheduler...
a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates.
the threat actor leverages PowerShell, BITSAdmin, and lightweight obfuscation techniques to stage and deploy SalatStealer
Pour échapper à la détection, le malware utilise plusieurs techniques d’évasion, notamment la compression de son code et la détection des environnements d’analyse.
T1027.002 — Obfuscated Files or Information: Software Packing (Defense Evasion)
main.NtQuerySystemHandles -- Handle enumeration (LSASS targeting) main.findLsassProcess -- LSASS process location
Il intègre également des fonctionnalités de surveillance, comme l’enregistrement des frappes clavier et la capture d’écran, lui permettant de récupérer davantage de données sensibles.
Son objectif principal est de voler des données sensibles sur les systèmes Windows, notamment les identifiants de connexion, les cookies de navigation, les informations enregistrées dans les navigateurs et les données associées aux portefeuilles de cryptomonnaies.
MITRE ATT&CK Mapping Technique ID Implementation Credentials in Files T1552.001 Browser profile data, wallet files
Son objectif principal est de voler des données sensibles sur les systèmes Windows, notamment les identifiants de connexion, les cookies de navigation, les informations enregistrées dans les navigateurs et les données associées aux portefeuilles de cryptomonnaies.
En plus du vol d’informations, SalatStealer collecte des renseignements sur le système compromis, tels que la configuration de la machine, les logiciels installés et les informations utilisateur.
Son objectif principal est de voler des données sensibles sur les systèmes Windows, notamment les identifiants de connexion, les cookies de navigation, les informations enregistrées dans les navigateurs et les données associées aux portefeuilles de cryptomonnaies.
The transport layer uses gorilla/websocket over HTTPS with QUIC/HTTP3 support (via quic-go). The C2 path is /saat/ with a WebSocket session protocol ( wsSess ) for bidirectional command execution.
dead drop resolver (DDR) is any mechanism where malware fetches its command and control (C2) address at runtime from a third-party, cyberattacker-controlled location instead of hardcoding it. | The loader posts JSON-RPC to the same high-reputation crypto SaaS hosts that wallets and decentralized applications use (Infura, Cloudflare, Binance, publicnode), so host-only network signatures drown in false positives.
the threat actor leverages PowerShell, BITSAdmin, and lightweight obfuscation techniques to stage and deploy SalatStealer
108 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A UPX-packed Windows payload assessed as SalatStealer was found alongside the camera-compromise tooling; the content characterizes it as unrelated to the primary Dahua camera campaign.
A Windows information-stealing payload identified in the operator's exposed materials. The content provides no further behavioral detail.
Windows information-stealing malware found staged alongside the operator's toolkit with a Microsoft Defender bypass script; the report explicitly treats it as unrelated to Operation CameraSwarm.
Commodity Go-based information stealer found staged on the same host, but the report explicitly says it is not directly linked to the camera-compromise campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.