logo

Salat Malware Abuses QUIC and WebSockets for Stealthy C2 Control

ID: 72f3b6c4-6397-5c46-8d47-4f39c1f19f3c

STIX ID: report--72f3b6c4-6397-5c46-8d47-4f39c1f19f3c

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

Salat Stealer is a Go-written Windows RAT/infostealer that combines credential and crypto-wallet theft, keylogging, remote shell/webcam/desktop streaming, SOCKS5 pivoting and persistence with stealth techniques (process masquerading, UPX packing). It uses QUIC/WebSocket (quic-go, gorilla/websocket) and HTTP/3 for low-noise C2, with doubly-encrypted embedded endpoints and a resilient TON blockchain/DNS-over-HTTPS fallback for fresh C2 retrieval; it also generates per-victim agent IDs and attempts privilege escalation. Analysts should monitor for masquerading binaries, suspicious scheduled tasks/Run keys, QUIC/WebSocket traffic, TON-related DoH activity, and behavioral EDR indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.