Salat Malware Abuses QUIC and WebSockets for Stealthy C2 Control
ID: 72f3b6c4-6397-5c46-8d47-4f39c1f19f3c
STIX ID: report--72f3b6c4-6397-5c46-8d47-4f39c1f19f3c
Feed Name: GBHackers
Salat Stealer is a Go-written Windows RAT/infostealer that combines credential and crypto-wallet theft, keylogging, remote shell/webcam/desktop streaming, SOCKS5 pivoting and persistence with stealth techniques (process masquerading, UPX packing). It uses QUIC/WebSocket (quic-go, gorilla/websocket) and HTTP/3 for low-noise C2, with doubly-encrypted embedded endpoints and a resilient TON blockchain/DNS-over-HTTPS fallback for fresh C2 retrieval; it also generates per-victim agent IDs and attempts privilege escalation. Analysts should monitor for masquerading binaries, suspicious scheduled tasks/Run keys, QUIC/WebSocket traffic, TON-related DoH activity, and behavioral EDR indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
