SalatStealer
- Malware type
- credential-stealer, spyware
- Last IoC activity
- 2026-07-22 04:04:45
- Profile updated
- 2026-07-07 15:19:04
Targeted industries: financial-services technology-and-telecommunications
Context
Crypto Stealer written in GO. Targets browsers, crypto wallets and telegram clients (Telegram Desktop, Kotatogram). Can capture webcam and microphone and stream it on to c2 server.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Salatstealer (report)
- blog.dexpose.io — Understanding Salatstealer Features And Impact (report)
- bazaar.abuse.ch — Salatstealer (report)