6d8ecdd14970065d66b9b2ecb3297a370d9a31241419ee6ec37a4069b7591085AFK Stealer v0.28.1 (x86)
Build / RE
Toolchain: Go 1.24.0, GOARCH=386, GOOS=windows — PE32 GUI subsystem. ^[rabin2-info.txt:18] ^[strings.txt:15425]
Packing: Standard UPX 3.96 outer compression (OpenCTI label upx-dec). Decompresses cleanly. Section entropy ~6.0 on .text/.rdata; no UPX strings remain post-decompress. ^[metadata.json] ^[pefile.txt]
Signing: Unsigned. ^[rabin2-info.txt:27]
Anti-analysis: None observed. No PEB walk, no CPUID hypervisor checks, no debug registers, no time gates. Go .symtab fully preserved with human-readable function names. ^[rabin2-info.txt:30]
Resources: No .rsrc, no version info, no icon. GUI subsystem with no visible window code. ^[pefile.txt]
Sections: .text (5.0 MB), .rdata (6.5 MB), .data (0.6 MB), .idata, .reloc, .symtab. ^[pefile.txt]
Dependencies: Identical module tree to sibling 0b6c65cd:
| Module | Version | Purpose |
|---|---|---|
github.com/quic-go/quic-go |
v0.38.1 | QUIC/HTTP3 C2 transport |
github.com/quic-go/quic-go/http3 |
v0.38.1 | HTTP/3 client round-tripper |
github.com/gorilla/websocket |
v1.5.3 | WebSocket fallback/exfil |
github.com/tetratelabs/wazero |
v1.8.2 | Wasm runtime (in-process plugin loader) |
github.com/ncruces/go-sqlite3 |
v0.23.0 | SQLite browser-credential DB parsing |
github.com/capnspacehook/taskmaster |
v0.0.0-20210519235353-1629df7c85e9 | Windows Task Scheduler persistence |
github.com/xssnick/tonutils-go |
v1.16.0 | TON blockchain address/wallet ops |
github.com/andygrunwald/vdf |
v1.1.0 | Steam local.vdf parsing |
github.com/go-ole/go-ole |
v1.2.6 | COM/OLE automation (Task Scheduler) |
github.com/yusufpapurcu/wmi + github.com/StackExchange/wmi |
v1.2.3 / v1.2.1 | WMI system enumeration |
^[strings.txt:15452-15469]
Deploy / ATT&CK
Family attribution: AFK Stealer (AFKSystems). Version string [AFK] 0.28.1 (x86) in plaintext. ^[strings.txt:10854] Second confirmed sibling after 0b6c65cd; same dependency versions, same target list, same build configuration.
Targets (concatenated on line 10854): Chrome, Edge, Brave, Opera, Opera GX, Firefox, Thunderbird, Yandex, SeaMonkey, Comodo Dragon, CocCoc, Chedot, Kometa, Fenrir, Coowon, Liebao, UR Browser, CentBrowser, Epic Privacy, 7Star, Maxthon3, QIP Surf, Chromium, Waterfox, K-Meleon, Cyberfox, BlackHaw, Mercury, Sputnik, MapleStudio, plus 40+ crypto wallets (Exodus, Armory, Guarda, MetaMask, TonKeeper, SuiWallet, AtomicWallet, Coin98, Fewcha, Finnie, Iconex, Kaikas, Oxygen, Pontem, Saturn, Sollet, Wombat, XMR.PT, XinPay, Electrum, MyMonero, Coinbase, Crocobit, Starcoin, Bytecoin, and many more). ^[strings.txt:10854]
TTPs:
- T1555.003 — Credentials from Web Browsers (SQLite + DPAPI via
go-sqlite3/wazero). - T1113 — Screen Capture (
salat/screenshotBitBlt + GDI+ bitmap creation). ^[strings.txt:25233] - T1115 — Clipboard Data (clipboard hijack for cryptocurrency addresses).
- T1082 — System Information Discovery (WMI
Win32_LogonSession,Win32_VideoController,MachineGuid). ^[strings.txt:8616] ^[strings.txt:10866] - T1543.001 — Create or Modify System Process: Windows Management Instrumentation (Task Scheduler via
taskmaster). ^[strings.txt:6659-8919] - T1547.001 — Registry Run Keys (
SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run). ^[strings.txt:10874] - T1071 — Application Layer Protocol: QUIC/HTTP3 (
quic-gov0.38.1 with TLS 1.3, X25519+MLKEM768, 0-RTT). ^[strings.txt:8923] - T1572 — Protocol Tunneling: DNS-over-HTTPS fallback (
https://1.1.1.1/dns-query). ^[strings.txt:10849] - T1567.001 — Exfiltration Over Web Service (JSON POST, Telegram bot integration:
found tg:// url,steal finished!). ^[strings.txt:10877] - T1083 — File and Directory Discovery (
os/exec,CreateToolhelp32Snapshot, browser-profile path enumeration). - T1497.001 — Virtualization/Sandbox Evasion: none observed (static-only, but no anti-VM strings).
C2 / Exfil:
- Primary: QUIC/HTTP3 via
quic-go. No hardcoded C2 domain or IP recovered from strings; configuration likely delivered at runtime or embedded in encrypted blob. - Fallback: DoH via Cloudflare (
1.1.1.1/dns-query). ^[strings.txt:10849] - WebSocket:
gorilla/websocketfor alternate channel. - Telegram:
found tg:// urlandsteal finished!confirmation strings. ^[strings.txt:10877] - Exfil format: ZIP archive (
sent.zip), JSON payload,application/octet-stream. ^[strings.txt:10874]
Persistence:
- Windows Task Scheduler (
taskmaster): supports boot, logon, daily, weekly, monthly, idle, and event triggers. ^[strings.txt:6659-8919] - Registry Run key as secondary. ^[strings.txt:10874]
Other observations:
- TON blockchain support (
tonutils-go) for wallet address generation/cell parsing. ^[strings.txt:9732] - Steam credential theft via
andygrunwald/vdf(local.vdfparsing). ^[strings.txt:9048] - Telegram Desktop data theft (
tdatabpaths). ^[strings.txt:10874] - Process enumeration and token manipulation (
OpenProcessToken,DuplicateTokenEx,CreateToolhelp32Snapshot). ^[strings.txt:10874] - ZIP compression for staging exfil. ^[strings.txt:10874]
Dynamic Notes
CAPE skipped — no Windows guest available. All behaviour inferred from static strings and Go module footprint. No observed C2 hardcoding; config likely runtime-resolved or encrypted. ^[dynamic-analysis.md]