typeanalysisfamilyafk-stealerconfidencehighcreated2026-08-15
SHA-256: 6d8ecdd14970065d66b9b2ecb3297a370d9a31241419ee6ec37a4069b7591085

AFK Stealer v0.28.1 (x86)

Build / RE

Toolchain: Go 1.24.0, GOARCH=386, GOOS=windows — PE32 GUI subsystem. ^[rabin2-info.txt:18] ^[strings.txt:15425] Packing: Standard UPX 3.96 outer compression (OpenCTI label upx-dec). Decompresses cleanly. Section entropy ~6.0 on .text/.rdata; no UPX strings remain post-decompress. ^[metadata.json] ^[pefile.txt] Signing: Unsigned. ^[rabin2-info.txt:27] Anti-analysis: None observed. No PEB walk, no CPUID hypervisor checks, no debug registers, no time gates. Go .symtab fully preserved with human-readable function names. ^[rabin2-info.txt:30] Resources: No .rsrc, no version info, no icon. GUI subsystem with no visible window code. ^[pefile.txt] Sections: .text (5.0 MB), .rdata (6.5 MB), .data (0.6 MB), .idata, .reloc, .symtab. ^[pefile.txt] Dependencies: Identical module tree to sibling 0b6c65cd:

Module Version Purpose
github.com/quic-go/quic-go v0.38.1 QUIC/HTTP3 C2 transport
github.com/quic-go/quic-go/http3 v0.38.1 HTTP/3 client round-tripper
github.com/gorilla/websocket v1.5.3 WebSocket fallback/exfil
github.com/tetratelabs/wazero v1.8.2 Wasm runtime (in-process plugin loader)
github.com/ncruces/go-sqlite3 v0.23.0 SQLite browser-credential DB parsing
github.com/capnspacehook/taskmaster v0.0.0-20210519235353-1629df7c85e9 Windows Task Scheduler persistence
github.com/xssnick/tonutils-go v1.16.0 TON blockchain address/wallet ops
github.com/andygrunwald/vdf v1.1.0 Steam local.vdf parsing
github.com/go-ole/go-ole v1.2.6 COM/OLE automation (Task Scheduler)
github.com/yusufpapurcu/wmi + github.com/StackExchange/wmi v1.2.3 / v1.2.1 WMI system enumeration

^[strings.txt:15452-15469]

Deploy / ATT&CK

Family attribution: AFK Stealer (AFKSystems). Version string [AFK] 0.28.1 (x86) in plaintext. ^[strings.txt:10854] Second confirmed sibling after 0b6c65cd; same dependency versions, same target list, same build configuration.

Targets (concatenated on line 10854): Chrome, Edge, Brave, Opera, Opera GX, Firefox, Thunderbird, Yandex, SeaMonkey, Comodo Dragon, CocCoc, Chedot, Kometa, Fenrir, Coowon, Liebao, UR Browser, CentBrowser, Epic Privacy, 7Star, Maxthon3, QIP Surf, Chromium, Waterfox, K-Meleon, Cyberfox, BlackHaw, Mercury, Sputnik, MapleStudio, plus 40+ crypto wallets (Exodus, Armory, Guarda, MetaMask, TonKeeper, SuiWallet, AtomicWallet, Coin98, Fewcha, Finnie, Iconex, Kaikas, Oxygen, Pontem, Saturn, Sollet, Wombat, XMR.PT, XinPay, Electrum, MyMonero, Coinbase, Crocobit, Starcoin, Bytecoin, and many more). ^[strings.txt:10854]

TTPs:

  • T1555.003 — Credentials from Web Browsers (SQLite + DPAPI via go-sqlite3/wazero).
  • T1113 — Screen Capture (salat/screenshot BitBlt + GDI+ bitmap creation). ^[strings.txt:25233]
  • T1115 — Clipboard Data (clipboard hijack for cryptocurrency addresses).
  • T1082 — System Information Discovery (WMI Win32_LogonSession, Win32_VideoController, MachineGuid). ^[strings.txt:8616] ^[strings.txt:10866]
  • T1543.001 — Create or Modify System Process: Windows Management Instrumentation (Task Scheduler via taskmaster). ^[strings.txt:6659-8919]
  • T1547.001 — Registry Run Keys (SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run). ^[strings.txt:10874]
  • T1071 — Application Layer Protocol: QUIC/HTTP3 (quic-go v0.38.1 with TLS 1.3, X25519+MLKEM768, 0-RTT). ^[strings.txt:8923]
  • T1572 — Protocol Tunneling: DNS-over-HTTPS fallback (https://1.1.1.1/dns-query). ^[strings.txt:10849]
  • T1567.001 — Exfiltration Over Web Service (JSON POST, Telegram bot integration: found tg:// url, steal finished!). ^[strings.txt:10877]
  • T1083 — File and Directory Discovery (os/exec, CreateToolhelp32Snapshot, browser-profile path enumeration).
  • T1497.001 — Virtualization/Sandbox Evasion: none observed (static-only, but no anti-VM strings).

C2 / Exfil:

  • Primary: QUIC/HTTP3 via quic-go. No hardcoded C2 domain or IP recovered from strings; configuration likely delivered at runtime or embedded in encrypted blob.
  • Fallback: DoH via Cloudflare (1.1.1.1/dns-query). ^[strings.txt:10849]
  • WebSocket: gorilla/websocket for alternate channel.
  • Telegram: found tg:// url and steal finished! confirmation strings. ^[strings.txt:10877]
  • Exfil format: ZIP archive (sent.zip), JSON payload, application/octet-stream. ^[strings.txt:10874]

Persistence:

  • Windows Task Scheduler (taskmaster): supports boot, logon, daily, weekly, monthly, idle, and event triggers. ^[strings.txt:6659-8919]
  • Registry Run key as secondary. ^[strings.txt:10874]

Other observations:

  • TON blockchain support (tonutils-go) for wallet address generation/cell parsing. ^[strings.txt:9732]
  • Steam credential theft via andygrunwald/vdf (local.vdf parsing). ^[strings.txt:9048]
  • Telegram Desktop data theft (tdatab paths). ^[strings.txt:10874]
  • Process enumeration and token manipulation (OpenProcessToken, DuplicateTokenEx, CreateToolhelp32Snapshot). ^[strings.txt:10874]
  • ZIP compression for staging exfil. ^[strings.txt:10874]

Dynamic Notes

CAPE skipped — no Windows guest available. All behaviour inferred from static strings and Go module footprint. No observed C2 hardcoding; config likely runtime-resolved or encrypted. ^[dynamic-analysis.md]