0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49aAnalysis: 0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a
1. Build / RE
Toolchain: Go 1.24.0 (go1.24.0), GOOS=windows, GOARCH=386. PE32 GUI executable, Intel 80386, 6 sections after decompression. ^[file.txt] ^[rabin2-info.txt]
Packing: Outer layer is UPX 3.96 (3 sections: UPX0, UPX1, UPX2). Standard upx -d decompresses cleanly to a 12.5 MB PE32 with intact Go metadata. ^[pefile.txt] ^[binwalk.txt]
Modules / Imports: Go module cache strings identify a rich dependency graph:
github.com/quic-go/quic-gov0.x — QUIC/HTTP3 C2 transport ^[strings-unpacked.txt:4052]github.com/tetratelabs/wazerov1.x — WebAssembly runtime embedded in-process ^[strings-unpacked.txt:6479]github.com/capnspacehook/taskmasterv0.0.0-20210519235353-1629df7c85e9 — Windows Task Scheduler OLE automation ^[strings-unpacked.txt:9572]github.com/ncruces/go-sqlite3v0.x — SQLite driver for browser database parsing ^[strings-unpacked.txt:4052]github.com/xssnick/tonutils-go— TON (The Open Network) blockchain address/wallet operations ^[strings-unpacked.txt:4052]golang.org/x/sys/windows,golang.org/x/crypto, standardnet/http,crypto/tls^[strings-unpacked.txt:4052]
Anti-analysis: None observed statically. No debug checks, no VM detection strings. The binary is stripped but retains Go .symtab-style function names (randomized main.* names are absent; names like main.getChromeCookies and main.getGeckoCookies are present). ^[strings-unpacked.txt:10877]
Signing / Resources: Unsigned. No .rsrc section, no version info, no icon. GUI subsystem with no visible window code. ^[pefile.txt] ^[rabin2-info.txt]
Notable functions:
main.getChromeCookies/main.getGeckoCookies— browser cookie harvesting ^[strings-unpacked.txt:10877]main.IElevatorVtblBrave/main.IElevatorVtblEdge— Brave/Edge credential vault access (IElevator COM interface for App-Bound Encryption bypass) ^[strings-unpacked.txt:7517]main.wsSess— WebSocket session struct ^[strings-unpacked.txt:4052]
2. Deploy / ATT&CK
TTPs:
| Technique | ID | Evidence |
|---|---|---|
| Credentials from Web Browsers | T1555.003 | main.getChromeCookies, main.getGeckoCookies, Login Data, logins.json, key4.db, Cookies, Local State ^[strings-unpacked.txt:10877] |
| Screen Capture | T1113 | PrintScreen, GetClipboardData, CreateCompatibleBitmap ^[strings-unpacked.txt:10866] |
| Clipboard Data | T1115 | Clipboard:, Clipboard: MachineGuid ^[strings-unpacked.txt:10866] |
| System Information Discovery | T1082 | HWID:, PC Name:, CPU:, GPU:, GEO:, MachineGuid, Select Name from Win32_Processor ^[strings-unpacked.txt:10854] |
| Create or Modify System Process | T1543 | github.com/capnspacehook/taskmaster, error creating registered task, StartBoundary, TaskTriggerType ^[strings-unpacked.txt:9572] |
| Application Layer Protocol | T1071 | quic-go, http3, quic iv, quic hp, quic key, WSAPoll ^[strings-unpacked.txt:4052] |
| Protocol Tunneling | T1572 | DoH endpoints https://1.1.1.1/dns-query, https://dns.google/resolve, https://cloudflare-dns.com/dns-query ^[strings-unpacked.txt:10859] |
| Exfiltration Over Web Service | T1567 | application/json, POST, steal finished!, found tg:// url, Telegram Desktop paths ^[strings-unpacked.txt:10877] |
| File and Directory Discovery | T1083 | Enumerates %LOCALAPPDATA%, %APPDATA%, browser profile paths for 15+ browsers ^[strings-unpacked.txt:10854] |
Persistence: Windows Task Scheduler via the taskmaster Go library. Supports boot, logon, daily, weekly, monthly, idle, and session-state-change triggers. ^[strings-unpacked.txt:9572]
C2 / Comms:
- Primary transport: QUIC/HTTP3 via
quic-go(TLS 1.3, 0-RTT, X25519+MLKEM768 key exchange). ^[strings-unpacked.txt:4052] - Fallback DNS: DNS-over-HTTPS (Cloudflare, Google, Quad9). ^[strings-unpacked.txt:10859]
- WebSocket framing present (
wsSess,WSAPoll). ^[strings-unpacked.txt:4052] - No hardcoded IP or domain in static strings; C2 likely resolved at runtime via DoH or embedded in WASM payload.
Targets:
- Browsers (15+): Chrome, Edge, Brave, Opera, Opera GX, Firefox, Thunderbird, Yandex, SeaMonkey, Comodo Dragon, CocCoc, 360Browser, UR Browser, CentBrowser, Epic Privacy Browser, etc. ^[strings-unpacked.txt:10854]
- Crypto Wallets (40+): Exodus, Armory, Guarda, MetaMask, TonKeeper, SuiWallet, AtomicWallet, Trust Wallet, Jaxx Liberty, TerraStation, Electrum, MyMonero, Coinbase, XMR.PT, and many more. ^[strings-unpacked.txt:10854] ^[strings-unpacked.txt:10858]
- Other: Telegram Desktop (
tdatabpaths), Steam (local.vdf), system clipboard, MachineGuid. ^[strings-unpacked.txt:10877]
Attribution:
Version string [AFK] 0.28.1 (x86) is present in plain text. ^[strings-unpacked.txt:10854] This identifies the sample as the AFK Stealer (also AFKSystems), a commodity Go-based infostealer sold on Russian-speaking forums. It is the ninth distinct build morph observed under the OpenCTI 54e64e umbrella label, but it is not build-related to the prior MSVC C++, .NET, or VB6 morphs — it is a separate family that shares only the opaque OpenCTI co-label.
Confidence: Medium for 54e64e umbrella membership; high for AFK Stealer attribution.
Dynamic analysis unavailable — CAPE skipped (no Windows guest). All behaviour inferred from static strings and imports.