family54e64e
SHA-256: 0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a

Analysis: 0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a

1. Build / RE

Toolchain: Go 1.24.0 (go1.24.0), GOOS=windows, GOARCH=386. PE32 GUI executable, Intel 80386, 6 sections after decompression. ^[file.txt] ^[rabin2-info.txt]

Packing: Outer layer is UPX 3.96 (3 sections: UPX0, UPX1, UPX2). Standard upx -d decompresses cleanly to a 12.5 MB PE32 with intact Go metadata. ^[pefile.txt] ^[binwalk.txt]

Modules / Imports: Go module cache strings identify a rich dependency graph:

  • github.com/quic-go/quic-go v0.x — QUIC/HTTP3 C2 transport ^[strings-unpacked.txt:4052]
  • github.com/tetratelabs/wazero v1.x — WebAssembly runtime embedded in-process ^[strings-unpacked.txt:6479]
  • github.com/capnspacehook/taskmaster v0.0.0-20210519235353-1629df7c85e9 — Windows Task Scheduler OLE automation ^[strings-unpacked.txt:9572]
  • github.com/ncruces/go-sqlite3 v0.x — SQLite driver for browser database parsing ^[strings-unpacked.txt:4052]
  • github.com/xssnick/tonutils-go — TON (The Open Network) blockchain address/wallet operations ^[strings-unpacked.txt:4052]
  • golang.org/x/sys/windows, golang.org/x/crypto, standard net/http, crypto/tls ^[strings-unpacked.txt:4052]

Anti-analysis: None observed statically. No debug checks, no VM detection strings. The binary is stripped but retains Go .symtab-style function names (randomized main.* names are absent; names like main.getChromeCookies and main.getGeckoCookies are present). ^[strings-unpacked.txt:10877]

Signing / Resources: Unsigned. No .rsrc section, no version info, no icon. GUI subsystem with no visible window code. ^[pefile.txt] ^[rabin2-info.txt]

Notable functions:

  • main.getChromeCookies / main.getGeckoCookies — browser cookie harvesting ^[strings-unpacked.txt:10877]
  • main.IElevatorVtblBrave / main.IElevatorVtblEdge — Brave/Edge credential vault access (IElevator COM interface for App-Bound Encryption bypass) ^[strings-unpacked.txt:7517]
  • main.wsSess — WebSocket session struct ^[strings-unpacked.txt:4052]

2. Deploy / ATT&CK

TTPs:

Technique ID Evidence
Credentials from Web Browsers T1555.003 main.getChromeCookies, main.getGeckoCookies, Login Data, logins.json, key4.db, Cookies, Local State ^[strings-unpacked.txt:10877]
Screen Capture T1113 PrintScreen, GetClipboardData, CreateCompatibleBitmap ^[strings-unpacked.txt:10866]
Clipboard Data T1115 Clipboard:, Clipboard: MachineGuid ^[strings-unpacked.txt:10866]
System Information Discovery T1082 HWID:, PC Name:, CPU:, GPU:, GEO:, MachineGuid, Select Name from Win32_Processor ^[strings-unpacked.txt:10854]
Create or Modify System Process T1543 github.com/capnspacehook/taskmaster, error creating registered task, StartBoundary, TaskTriggerType ^[strings-unpacked.txt:9572]
Application Layer Protocol T1071 quic-go, http3, quic iv, quic hp, quic key, WSAPoll ^[strings-unpacked.txt:4052]
Protocol Tunneling T1572 DoH endpoints https://1.1.1.1/dns-query, https://dns.google/resolve, https://cloudflare-dns.com/dns-query ^[strings-unpacked.txt:10859]
Exfiltration Over Web Service T1567 application/json, POST, steal finished!, found tg:// url, Telegram Desktop paths ^[strings-unpacked.txt:10877]
File and Directory Discovery T1083 Enumerates %LOCALAPPDATA%, %APPDATA%, browser profile paths for 15+ browsers ^[strings-unpacked.txt:10854]

Persistence: Windows Task Scheduler via the taskmaster Go library. Supports boot, logon, daily, weekly, monthly, idle, and session-state-change triggers. ^[strings-unpacked.txt:9572]

C2 / Comms:

  • Primary transport: QUIC/HTTP3 via quic-go (TLS 1.3, 0-RTT, X25519+MLKEM768 key exchange). ^[strings-unpacked.txt:4052]
  • Fallback DNS: DNS-over-HTTPS (Cloudflare, Google, Quad9). ^[strings-unpacked.txt:10859]
  • WebSocket framing present (wsSess, WSAPoll). ^[strings-unpacked.txt:4052]
  • No hardcoded IP or domain in static strings; C2 likely resolved at runtime via DoH or embedded in WASM payload.

Targets:

  • Browsers (15+): Chrome, Edge, Brave, Opera, Opera GX, Firefox, Thunderbird, Yandex, SeaMonkey, Comodo Dragon, CocCoc, 360Browser, UR Browser, CentBrowser, Epic Privacy Browser, etc. ^[strings-unpacked.txt:10854]
  • Crypto Wallets (40+): Exodus, Armory, Guarda, MetaMask, TonKeeper, SuiWallet, AtomicWallet, Trust Wallet, Jaxx Liberty, TerraStation, Electrum, MyMonero, Coinbase, XMR.PT, and many more. ^[strings-unpacked.txt:10854] ^[strings-unpacked.txt:10858]
  • Other: Telegram Desktop (tdatab paths), Steam (local.vdf), system clipboard, MachineGuid. ^[strings-unpacked.txt:10877]

Attribution: Version string [AFK] 0.28.1 (x86) is present in plain text. ^[strings-unpacked.txt:10854] This identifies the sample as the AFK Stealer (also AFKSystems), a commodity Go-based infostealer sold on Russian-speaking forums. It is the ninth distinct build morph observed under the OpenCTI 54e64e umbrella label, but it is not build-related to the prior MSVC C++, .NET, or VB6 morphs — it is a separate family that shares only the opaque OpenCTI co-label.

Confidence: Medium for 54e64e umbrella membership; high for AFK Stealer attribution.


Dynamic analysis unavailable — CAPE skipped (no Windows guest). All behaviour inferred from static strings and imports.