SalatStealer

Malware type
credential-stealer, spyware
Last IoC activity
2026-07-22 04:04:45
Profile updated
2026-07-07 15:19:04

Targeted industries: financial-services technology-and-telecommunications

Context

Crypto Stealer written in GO. Targets browsers, crypto wallets and telegram clients (Telegram Desktop, Kotatogram). Can capture webcam and microphone and stream it on to c2 server.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Salatstealer (report)
  • blog.dexpose.io — Understanding Salatstealer Features And Impact (report)
  • bazaar.abuse.ch — Salatstealer (report)

External references