logo

New Salat Malware Uses QUIC and WebSocket Channels for Stealthy Remote Control

ID: a644b7b9-c6fb-59bf-8898-a041f9119bce

STIX ID: report--a644b7b9-c6fb-59bf-8898-a041f9119bce

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Tushar Subhra Dutta

...
...

Salat is a sophisticated Go-based remote access trojan offering extensive data theft (browsers, crypto wallets, messaging tokens, clipboard), live desktop and webcam streaming, keystroke logging, remote shell access, and multiple persistence mechanisms. It uses QUIC and WebSocket to blend communications with legitimate traffic, stores doubly-encrypted C2 addresses with a TON blockchain fallback for resiliency, and includes IoCs (hashes and C2 URLs) published by researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.