
"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory blocks. Includes C2 domains, Go build ID, and obfuscated payload extraction."
When executed, Salat Stealer displays a fully functional Telegram Proxy interface. This decoy serves as a camouflage to trick the user into thinking they are running a legitimate proxy application, while the malware executes its malicious operations in the background.
proxy.telegram.org).443 (standard HTTPS port) to blend in with normal traffic.
The fake Telegram Proxy interface used by Salat Stealer to disguise its malicious activity.
One of the most critical findings in this analysis is the presence of plaintext C2 addresses and a Go Build ID in the binary's strings section. This oversight reveals the malware's infrastructure and helps track its origins.
j.sni.global.fastly.net – Likely a CDN-based C2 server.ton.access.orbs.network – Possibly related to TON or Orbs Network, used for crypto wallet theft.soaSZ3gtdf5oZjHHPnzB/... – This unique identifier can be used to track the malware's build environment.
Process Hacker strings view showing C2 addresses and Go Build ID.
Salat Stealer uses token manipulation to grant itself full access to system resources. The code constructs a security descriptor with FILE_ALL_ACCESS permissions, allowing the malware to read, write, and delete critical files.
GetCurrentProcess() – Gets the current process handle.TokenUser – Retrieves the user SID for ACL creation.TokenAppContainerSid – Retrieves the AppContainer SID (if applicable).ConvertStringSecurityDescriptorToSecurityDescriptorW – Converts a string-based ACL to a binary security descriptor.FILE_ALL_ACCESS – Grants full control over files and directories.
Ghidra view of the token manipulation and security descriptor creation code.
One of the extracted PAGE_READWRITE memory blocks (64 KB) contains heavily obfuscated data. The hex dump shows repeating patterns and structured bytes, indicating this is likely an encrypted configuration or compressed payload.
\x50\xd7\x5c\x22 type patterns) suggest a structured format.PAGE_READWRITE memory region, typical of obfuscated malware payloads.
Binary Ninja view of the obfuscated hex data from a 64KB PAGE_READWRITE memory block.
A second PAGE_READWRITE memory block (32 KB) was analyzed and found to contain the Turkish error message: "vaya erişilmeye çalışıldı." (roughly: "Oops, attempted to access."). This suggests the malware developer may be Turkish or the sample was developed in a Turkish-speaking environment.
"vaya erişilmeye çalışıldı." – Likely a debug or error message.
Binary Ninja view of the 32KB obfuscated block with the Turkish error message.
This analysis uncovered Salat Stealer, a sophisticated Go-based info-stealer that uses a Telegram proxy decoy to evade detection. Despite heavy obfuscation, the malware left critical artifacts in its strings section, revealing C2 addresses, a Go Build ID, and a Turkish error message.
j.sni.global.fastly.net and ton.access.orbs.network are used for data exfiltration.FILE_ALL_ACCESS) to system resources.PAGE_READWRITE memory blocks (32KB and 64KB) were found to contain encrypted or compressed data."vaya erişilmeye çalışıldı." suggests the developer may be Turkish.j.sni.global.fastly.net, ton.access.orbs.network.FILE_ALL_ACCESS attempts.PAGE_READWRITE memory regions in suspicious processes.The analyzed Salat Stealer sample is available on MalwareBazaar for those who wish to conduct their own analysis:
🔗 Salat Stealer Sample on MalwareBazaar
Tools Used: Ghidra, Binary Ninja, Process Hacker, WinDbg