Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis — "Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory blocks. Includes C2 domains, Go build ID, and obfuscated payload extraction." | Kitploit
Tools/GitHubGitHub/kaandemir993/salat-stealer-telegram-proxy-decoy-c2-analysis
Reverse EngineeringForensicsInformation GatheringMalware AnalysisCommand and ControlBinary AnalysisThreat IntelligencePapers & ResearchLearning & Education

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHubkaandemir993/salat-stealer-telegram-proxy-decoy-c2-analysis

Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory blocks. Includes C2 domains, Go build ID, and obfuscated payload extraction."

View Repository
51252 months agoNot yet reviewed
Share

1. Telegram Proxy Decoy – Camouflage & Evasion

When executed, Salat Stealer displays a fully functional Telegram Proxy interface. This decoy serves as a camouflage to trick the user into thinking they are running a legitimate proxy application, while the malware executes its malicious operations in the background.

Key Observations:

  • Interface: The window mimics a legitimate Telegram Proxy client (proxy.telegram.org).
  • Port: Uses port 443 (standard HTTPS port) to blend in with normal traffic.
  • Protocol: MTProto 2.0 (Telegram's protocol) is displayed to appear authentic.
  • Behavior: Clicking "Connect" establishes a connection, but the malware's payload is already active in the background.

Why This Matters:

  • Camouflage: The user is less likely to suspect a harmless proxy app.
  • Evasion: Security tools may overlook the process as legitimate Telegram traffic.
  • Persistence: The malware can continue running even if the user closes the window.

Visual Reference:

Salat Stealer Telegram Proxy Decoy The fake Telegram Proxy interface used by Salat Stealer to disguise its malicious activity.

2. Strings Analysis – C2 Addresses & Go Build ID

One of the most critical findings in this analysis is the presence of plaintext C2 addresses and a Go Build ID in the binary's strings section. This oversight reveals the malware's infrastructure and helps track its origins.

Key Observations:

  • C2 Addresses:
    • j.sni.global.fastly.net – Likely a CDN-based C2 server.
    • ton.access.orbs.network – Possibly related to TON or Orbs Network, used for crypto wallet theft.
  • Go Build ID: soaSZ3gtdf5oZjHHPnzB/... – This unique identifier can be used to track the malware's build environment.

Why This Matters:

  • C2 Communication: These addresses are used for data exfiltration and command delivery.
  • Tracking: The Go Build ID helps link this sample to other variants or campaigns.
  • Detection: Network security tools can block these domains.

Visual Reference:

Salat Stealer Strings Analysis Process Hacker strings view showing C2 addresses and Go Build ID.

3. Token Manipulation – Privilege Escalation

Salat Stealer uses token manipulation to grant itself full access to system resources. The code constructs a security descriptor with FILE_ALL_ACCESS permissions, allowing the malware to read, write, and delete critical files.

What This Code Does:

  • GetCurrentProcess() – Gets the current process handle.
  • TokenUser – Retrieves the user SID for ACL creation.
  • TokenAppContainerSid – Retrieves the AppContainer SID (if applicable).
  • ConvertStringSecurityDescriptorToSecurityDescriptorW – Converts a string-based ACL to a binary security descriptor.
  • FILE_ALL_ACCESS – Grants full control over files and directories.

Why This Matters:

  • Privilege Escalation: The malware can bypass security restrictions.
  • Persistence: Full access allows the malware to modify registry keys and system files.
  • Evasion: With high privileges, the malware can hide from security tools.

Visual Reference:

Salat Stealer Token Manipulation Ghidra view of the token manipulation and security descriptor creation code.

4. Obfuscated Payload – Encrypted Memory Block

One of the extracted PAGE_READWRITE memory blocks (64 KB) contains heavily obfuscated data. The hex dump shows repeating patterns and structured bytes, indicating this is likely an encrypted configuration or compressed payload.

Key Observations:

  • Size: 64 KB – Large enough to contain a configuration or payload.
  • Pattern: Repeating structures (\x50\xd7\x5c\x22 type patterns) suggest a structured format.
  • Readable Strings: None visible, confirming the data is encrypted or compressed.
  • Location: Found in a PAGE_READWRITE memory region, typical of obfuscated malware payloads.

Why This Matters:

  • Payload Extraction: This block may contain the final stealer components or C2 configuration.
  • Encryption: The data is likely protected with XOR or AES, requiring a key for decryption.
  • Analysis Challenge: Obfuscation prevents direct static analysis, making dynamic analysis essential.

Visual Reference:

Salat Stealer Obfuscated Payload Binary Ninja view of the obfuscated hex data from a 64KB PAGE_READWRITE memory block.

5. Second Obfuscated Block – Turkish Error Message

A second PAGE_READWRITE memory block (32 KB) was analyzed and found to contain the Turkish error message: "vaya erişilmeye çalışıldı." (roughly: "Oops, attempted to access."). This suggests the malware developer may be Turkish or the sample was developed in a Turkish-speaking environment.

Key Observations:

  • Size: 32 KB – Smaller than the previous block.
  • Turkish String: "vaya erişilmeye çalışıldı." – Likely a debug or error message.
  • Obfuscation: The rest of the block is heavily obfuscated or encrypted.
  • Possible Context: Could indicate failed file access or API call.

Why This Matters:

  • Developer Origin: The Turkish string suggests the author may be Turkish.
  • Debugging Artifact: This message may have been left unintentionally, revealing developer habits.
  • Threat Intelligence: This can help link this sample to other campaigns.

Visual Reference:

Salat Stealer Second Obfuscated Block Binary Ninja view of the 32KB obfuscated block with the Turkish error message.

Conclusion

This analysis uncovered Salat Stealer, a sophisticated Go-based info-stealer that uses a Telegram proxy decoy to evade detection. Despite heavy obfuscation, the malware left critical artifacts in its strings section, revealing C2 addresses, a Go Build ID, and a Turkish error message.

Key Takeaways:

  • Telegram Proxy Decoy: The malware disguises itself as a legitimate Telegram Proxy to trick users.
  • C2 Infrastructure: Domains like j.sni.global.fastly.net and ton.access.orbs.network are used for data exfiltration.
  • Token Manipulation: The malware grants itself full access (FILE_ALL_ACCESS) to system resources.
  • Obfuscated Payload: Two PAGE_READWRITE memory blocks (32KB and 64KB) were found to contain encrypted or compressed data.
  • Turkish Error Message: "vaya erişilmeye çalışıldı." suggests the developer may be Turkish.

Detection Recommendations:

  • Monitor for Telegram Proxy decoy behavior.
  • Block C2 domains: j.sni.global.fastly.net, ton.access.orbs.network.
  • Detect token manipulation and FILE_ALL_ACCESS attempts.
  • Investigate PAGE_READWRITE memory regions in suspicious processes.

Sample Download

The analyzed Salat Stealer sample is available on MalwareBazaar for those who wish to conduct their own analysis:

🔗 Salat Stealer Sample on MalwareBazaar

Tools Used: Ghidra, Binary Ninja, Process Hacker, WinDbg

Download Tool