logo

Salat Malware Abuses WebSocket Channels To Evade Detection

ID: b38f368e-c7bf-561b-a6f1-62ff4e2ed959

STIX ID: report--b38f368e-c7bf-561b-a6f1-62ff4e2ed959

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Varshini

...
...

Salat Stealer is a sophisticated Go-based RAT and infostealer that combines credential and cryptocurrency wallet theft with full remote-access capabilities (shell, desktop/webcam streaming, microphone access, SOCKS5 pivoting). It uses WebSocket and HTTP/3 (QUIC) for covert C2, derives hardware-bound cryptographic keys, abuses DPAPI to decrypt browser-stored secrets, attempts privilege escalation, and implements a resilient TON blockchain fallback for C2 endpoints, enabling persistent, hard-to-takedown operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.