Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

SalatStealer

13
Global rank
16 infographic chevron month
Month rank
13
Week rank
0
IOCs

SalatStealer, also known as WEB_RAT or Salat Stealer, is a Go-based information-stealing malware targeting Windows systems. It operates as a Malware-as-a-Service (MaaS) focusing on harvesting browser credentials, cryptocurrency wallets, and session data from popular applications like Telegram and Steam.

Stealer
Type
Unknown
Origin
1 August, 2025
First seen
11 August, 2026
Last seen

How to analyze SalatStealer with ANY.RUN

Type
Unknown
Origin
1 August, 2025
First seen
11 August, 2026
Last seen

IOCs

IP addresses
162.159.136.234
23.194.190.159
74.178.240.61
162.159.207.0
104.16.248.249
150.171.27.11
104.17.208.5
92.123.104.64
204.79.197.203
1.1.1.1
48.209.133.15
35.190.80.1
192.178.183.94
199.232.210.172
2.21.110.198
162.159.134.233
172.67.145.43
104.26.10.174
135.236.137.147
95.100.135.107
Hashes
1967da158234d42db7bddffea780b95eacb916af2731194a2369650ac66ae7ba
6238cbfe9f57c142b75e153c399c478d492252fda8cb40ee539c2dcb0f2eb232
b393f05e8ff919ef071181050e1873c9a776e1a0ae8329aefff7007d0cadf592
b72e9013a6204e9f01076dc38dabbf30870d44dfc66962adbf73619d4331601e
be4b8924ab38e8acf350e6e3b9f1f63a1a94952d8002759acd6946c4d5d0b5de
5154e165bd6c2cc0cfbcd8916498c7abab0497923bafcd5cb07673fe8480087d
313818d6b177a70fbe715a5142d6221ac1a1851eff5a9f6df505670ddcd73074
7353f25dc5cf84d09894e3e0461cef0e56799adbc617fce37620ca67240b547d
7152a6933ee3d690ec2af3d09da9d701723d16aa3410a6d80f28ff8866f3b880
f7c6c7ea22edd2f8bd07aa5b33cbce862ef1dcdc2226eb130e0018e02ff91dc1
e2e4d97c20d4478e8e947480c8f6c71a2c795776d405366be70db82e4ea4ba77
ede865b11b6817ee43248aa61e18b30ccce9a421058595296c2d58f59c118aee
25c6e3c6d07bdb5da55495099063a7de01f357c16de71d5d65ca51e4cf8d0e8a
3269cf3fda7681388472225bad39b6bb3b26088a0a03b6cd5796195f0114ce13
862046fee1b4f3744f000347cc0b337871967b2bd9471bcb6dded2a49a61c527
f860149a77a53d43396f3aec9377b9a0dd6c5d84459079c5d393f6343ec253fb
075de1d6ea4fb470197a88ba371f60f70b819b250cb5af8bd6a4794b1a9ca4a1
cb4fd141a5c4d188a3ecb203e9d41a3afca648724160e212289adcac666fbff4
7bb75adef02d28819f1bd3b42fa46ed56d6dfbeae072341997b09b8c1f52d8dc
e8f03c2e9c88adb04648ef93f9ea3cff87641638ac97c9a6752b751e7f7a8a20
Domains
edge.microsoft.com
stun.l.google.com
img-s-msn-com.akamaized.net
r.bing.com
oneocsp.microsoft.com
nexusrules.officeapps.live.com
dns.google
msedge.b.tlu.dl.delivery.mp.microsoft.com
www.investmentnews.com
a.nel.cloudflare.com
cdn.discordapp.com
th.bing.com
edge-cloud-resource-static.azureedge.net
login.live.com
discord.gg
go.microsoft.com
www.bing.com
login.microsoftonline.com
stun1.l.google.com
r.msftstatic.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:yxezmujpv_6szkclwtl6nby3a-nkhne9ejnxalf4dhu&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d235%2526e%253d1
https://cdn.discordapp.com/attachments/1524058480384938128/1536669126167240754/robloxscanner.exe?ex=6a7c3e25&is=6a7aeca5&hm=8b95a73e34a272a63c3c0b1ac3f35c887785d0c3a127f8bd68b1966cbf59f2fc&
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://copilot.microsoft.com/c/api/user/eligibility
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://update.googleapis.com/service/update2/json?cup2key=14:xttiuveytvbkneiuu56admcafwvqan52b-7t0hgfwya&cup2hreq=cbee6ef1ce7190906e77ffb34203045050e9077a5ce39027ce47010c69d257c0
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://clients2.googleusercontent.com/crx/blobs/auu14h9lifl_xdfovyc6ev9d9ia6qcy2fpggd1uevuk_yoqwcsmd13fexvuvu2cn93z41_hou8y7vuivvhjkvqkxhviwy8eqaszi6uvsh8cwzz02zvegbus0d2hnwvroeqeaxlka5cc_zznn-sn4gcvn46um6ojs-psr/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_108_1_0.crx
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://ntp.msn.com/edge/ntp?locale=en-us&title=new%20tab&dsp=1&sp=bing&pc=u531
https://ntp.msn.com/bundles/v1/edgechromium/latest/ssr-extension.70bd5df3e48d107c.js
https://ntp.msn.com/bundles/v1/edgechromium/latest/web-worker.7edb9699e0482d47.js
https://assets.msn.com/staticsb/statics/latest/mscmp/1.7/entry.js

Recent blog posts

post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 406
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 15086
comments 0
post image
Safeguarding 200M Users: How ChongLuaDao Scal...
watchers 7577
comments 0

Beware SalatStealer – Stealthy Stealer Harvesting Browsers, Wallets, and Webcams

Key Takeaways

  1. SalatStealer is a Go-based Windows infostealer targeting browsers, crypto wallets, and app sessions.
  2. It uses advanced evasion like UPX packing, UAC bypass, and process masquerading.
  3. Distributed mainly via fake cracks and cheats on YouTube and forums.
  4. Persistence through registry keys and scheduled tasks ensures long-term access.
  5. Real-time surveillance features like webcam/microphone capture heighten privacy risks.
  6. Use TI Lookup to quickly check suspicious files, domains, or hashes for SalatStealer indicators.

destinationIP:"45.130.41.157".

IP detected as SalatStealer Suspicious IP detected as SalatStealer, plus targeted sectors

  1. Analyze threats interactively in ANY.RUN’s Sandbox to uncover SalatStealer’s full behavior and IOCs safely. View analysis

SalatStealer sample in Interactive Sandbox SalatStealer detonated in ANY.RUN’s Sandbox

What is SalatStealer Malware?

SalatStealer, also tracked as WEB_RAT, is a sophisticated information-stealing malware that targets Windows systems. First detected in August 2025, it has quickly established itself as a significant cybersecurity threat, combining extensive data theft capabilities with aggressive persistence mechanisms and real-time surveillance features.

What sets SalatStealer apart is its approach to data exfiltration. The malware doesn't just steal credentials. It harvests browser data, cryptocurrency wallets, messaging application sessions, system information, and even streams live video and audio from infected devices. Operating under a Malware-as-a-Service model, SalatStealer has become accessible to a broad range of cybercriminals, amplifying its reach and potential impact.

Written in Golang version 1.22.0, SalatStealer leverages the cross-platform capabilities and performance characteristics of the Go language. The developers have taken additional steps to hinder analysis by stripping all debugging symbols from the compiled binary, making reverse engineering significantly more challenging.

The malware employs multiple anti-analysis techniques, including virtual machine detection, mutex creation to prevent reinfection of the same device, and checks for debugging environments. These defensive measures help SalatStealer evade both automated sandbox analysis and manual reverse engineering attempts.

Upon execution, SalatStealer first checks if the infected system is connected to the internet by sending GET requests to specific URLs, automatically exiting if connectivity is not detected. This preliminary check ensures the malware operates only in environments where it can successfully communicate with its command-and-control infrastructure.

Often packed with UPX to increase entropy and hinder static analysis, the persistence mechanisms include registry run keys and scheduled tasks disguised as legitimate processes (e.g., Lightshot.exe or RuntimeBroker). It communicates with command-and-control (C2) servers via encrypted HTTPS channels and lightweight UDP beacons, using domains like salat[.]cn with multiple fallbacks for resilience. Operated through a web-based panel branded "WebRat," it is sold on underground forums for low subscription fees, making it accessible to a wide range of cybercriminals.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Salat Stealer Victimology

SalatStealer primarily targets opportunistic victims, such as individuals downloading pirated software, game cheats, or cracks from untrusted sources like YouTube links and file sharing sites. Its focus on cryptocurrency wallets and browser credentials suggests a strong interest in crypto enthusiasts and everyday users storing sensitive logins. While no specific geographic or sectoral targeting has been reported, the malware's broad capabilities make it a threat to both individual users and employees in organizations who fall for social engineering lures on personal devices.

How SalatStealer Threatens Businesses and Organizations

SalatStealer poses significant risks to business environments:

  • Credential compromise leads to account takeovers and lateral movement.

  • Exfiltrated session tokens can bypass multifactor protections.

  • Corporate browser credential theft exposes enterprise SSO and internal portals.

  • Cryptocurrency asset theft impacts any organization handling digital assets.

  • Long-term persistence creates opportunities for further exploitation and deeper intrusion.

  • Malware can undermine endpoint defenses by creating exclusion rules and disabling protective tools.

How SalatStealer Malware Gets in and Functions

Primary infection vectors include:

  • Phishing campaigns luring users to open malicious archives or executables.
  • Social engineering through cracked software, fake utilities, or rogue downloads.
  • Malicious advertisements or compromised websites serving infected files.
  • Bundling with trojanized installers.

The malware sample is packed using UPX version 0.89 or higher, with all sections in the PE file compressed or encrypted to hide the real program instructions. Upon execution, the malware unpacks itself in memory, revealing its true functionality while avoiding disk-based detection.

Before proceeding with malicious activities, SalatStealer verifies internet connectivity to ensure it can communicate with its command-and-control servers.

Salat initiates multiple processes and attempts to evade detection by disguising itself as a legitimate application, creating several child processes named Lightshot.exe, which are dropped into directories that appear to belong to trusted software.

To maintain persistence on infected systems, the malware creates multiple Run key entries in the Windows Registry, registering itself under different names (Lightshot, Procmon, and RuntimeBroker) to further evade detection by mimicking legitimate system or third-party processes. It utilizes Windows Task Scheduler to create scheduled tasks under deceptive names, each configured with multiple triggers.

A "Defender Excluder" script module quietly adds critical directories to Windows Defender's exclusion list, ensuring that neither the main payload nor its auxiliary tools are scanned.

The malware systematically enumerates and harvests data from multiple sources. It accesses browser SQLite databases to extract credentials, scans specific directories for cryptocurrency wallet files and configurations, monitors active windows to identify sensitive applications, and captures screenshots and video streams when appropriate.

It compresses collected data and exfiltrates it to command-and-control servers over the Quick UDP Internet Connections (QUIC) protocol.

The platform includes real-time WebSocket communication, remote PowerShell execution capabilities, and predefined scripts for Windows Defender exclusion manipulation, UAC disabling, and recovery environment disabling.

Sandbox Analysis of a SalatStealer Sample

ANY.RUN’s Interactive Sandbox overcomes Salat’s ant-detection and sandbox-evasion mechanics, exposing the full attack chain. For SalatStealer, the Sandbox can reveal unpacking routines, persistence mechanisms, network communications, and data exfiltration attempts.

View a SalatStealer sample analysis

SalatStealer Sandbox analysis SalatStealer detonated in the Interactive Sandbox

The main process spawns a child process lsass.exe. Domain resolution attempts for salat.cn were detected, but further network activity is absent due to the inactive C2 server.

Domain connection attempt Domain connection attempt

The sample is written in the Go language and packed with UPX which are detected by the Sandbox. It also reveals elliptic curves (YARA) that are used for encryption.

Malware features Malware features detected by the Sandbox

Registry queries extract basic data: computer name for victim identification, machine GUID for unique marking, and checking supported languages for locale adaptation. This forms a system profile, helping the malware select targets for data theft.

System data gathering System data gathering

The sample drops itself into trusted directories and masquerades under system names, making the process resemble built-in Windows components.

SalatStealer processes SalatStealer’s processes

Signing in the Task Scheduler ensures automatic launch. The malware creates tasks with multiple triggers: at user logon and a one-time launch at a specific time.

SalatStealer in Windows tasks SalatStealer in Windows tasks

Browser data exfiltration focuses on passwords, cookies, and sessions stored in databases like SQLite. Wallet extension IDs were detected for potential theft of funds, and functionality for stealing messenger data is also observed.

Credential harvesting and data theft Credential harvesting and data theft

Gathering Threat Intelligence on SalatStealer Malware

Threat intelligence services like ANY.RUN’s TI Lookup aggregate information about SalatStealer campaigns, including indicators of compromise, C2 infrastructure, file hashes, and tactics, techniques, and procedures. This intelligence enables proactive defense by allowing organizations to block known malicious infrastructure before infection attempts occur.

A threat name lookup can tell whether your business sector and geographical location are actively targeted by SalatStealer, deliver IOCs, and malware samples analyzed in the Sandbox:

threatName:"salat"

SalatStealer threat intelligence lookup data Use TI Lookup to gather Salat Stealer IOCs and view sandbox analyses

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

SalatStealer represents a serious evolution in infostealer malware: resilient, stealthy, and offered under a MaaS model that lowers the barrier to entry for attackers. Its ability to extract credentials, wallets, and sessions combined with evasion and persistence tactics make it a formidable threat at both the individual and enterprise level. Detection depends on robust modern security tooling and threat intelligence, while prevention hinges on user training, hygiene, and proactive defenses.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Lumma screenshot
Lumma
lumma
Lumma is an information stealer, developed using the C programming language. It is offered for sale as a malware-as-a-service, with several plans available. It usually targets cryptocurrency wallets, login credentials, and other sensitive information on a compromised system. The malicious software regularly gets updates that improve and expand its functionality, making it a serious stealer threat.
Read More
Stealc screenshot
Stealc
stealc
Stealc is a stealer malware that targets victims’ sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server through HTTP POST requests.
Read More
PXA Stealer screenshot
PXA Stealer
pxastealer
PXA Stealer is an information-stealing malware that targets individuals and organizations in 60+ countries. It spreads via phishing, archives, and fake software updates. DLL sideloading, decoy documents, and obfuscation help it evade security tools. Exfiltrated data is exfiltrated and monetized through underground marketplaces.
Read More
WarmCookie screenshot
WarmCookie
badspace
WarmCookie is a backdoor malware that cyber attackers use to gain initial access to targeted systems. It is often distributed through phishing emails, frequently using job recruitment lures to entice victims into downloading and executing the malware.
Read More
Neptune RAT screenshot
Neptune RAT is a Visual Basic .NET remote access trojan that gives attackers full control over infected Windows machines while stealing credentials from 270+ applications, hijacking cryptocurrency transactions, spying on victims in real time, and, in its most destructive mode, wiping the operating system entirely. Marketed openly on GitHub, Telegram, and YouTube as the "Most Advanced RAT," it is distributed under a malware-as-a-service model.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More