Salat Malware Abuses WebSocket Channels To Evade Detection
ID: b38f368e-c7bf-561b-a6f1-62ff4e2ed959
STIX ID: report--b38f368e-c7bf-561b-a6f1-62ff4e2ed959
Feed Name: Cyber Press
Salat Stealer is a sophisticated Go-based RAT and infostealer that combines credential and cryptocurrency wallet theft with full remote-access capabilities (shell, desktop/webcam streaming, microphone access, SOCKS5 pivoting). It uses WebSocket and HTTP/3 (QUIC) for covert C2, derives hardware-bound cryptographic keys, abuses DPAPI to decrypt browser-stored secrets, attempts privilege escalation, and implements a resilient TON blockchain fallback for C2 endpoints, enabling persistent, hard-to-takedown operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
