familyafk-stealerconfidencehighcreated2026-08-18updated2026-08-18
SHA-256: b07d5dcd0cb2b95480328ff64456f811d917763b53f0e3403969093383a90014

AFK Stealer 0.28.1 (x86) — b07d5dcd

1. Build / RE

Packing: UPX-compressed outer shell (Likely_Packer_UPX YARA hit; upx -d expands 3.6 MB → 12.6 MB). ^[yara.txt] Post-decompression yields a PE32 executable (GUI) Intel 80386, 6 sections, no .rsrc, no version info, no icon. ^[file.txt]

Toolchain: Go 1.24.0, GOOS=windows, GOARCH=386, module name salat (devel build). ^[strings-unpacked.txt:6957] No build timestamp; PE timestamp is zeroed. ^[exiftool.json]

Signing: Unsigned. No Authenticode or self-signed certificate.

Anti-analysis: None observed. No debug checks, VM detection, or anti-disassembly in static surface. Stripped but retains Go .symtab function names.

Embedded resources: No icon or manifest. Standard Go runtime with CGO disabled (pure Go). The wazero WebAssembly runtime is present, suggesting optional WASM module loading at runtime. ^[strings-unpacked.txt:6973]

Dependencies (Go modules) — identical dep graph to siblings 0b6c65cd and 6d8ecdd1:

Module Version Purpose
github.com/quic-go/quic-go v0.38.1 QUIC/HTTP3 C2 transport
github.com/gorilla/websocket v1.5.3 WebSocket fallback
github.com/tetratelabs/wazero v1.8.2 WASM runtime (in-process module loader)
github.com/capnspacehook/taskmaster v0.0.0-20210519235353-1629df7c85e9 Windows Task Scheduler persistence
github.com/ncruces/go-sqlite3 v0.23.0 SQLite driver for browser DB parsing
github.com/xssnick/tonutils-go v1.16.0 TON blockchain wallet operations
github.com/andygrunwald/vdf v1.1.0 Steam local.vdf parsing
github.com/StackExchange/wmi v1.2.1 WMI queries (system reconnaissance)
github.com/yusufpapurcu/wmi v1.2.3 WMI queries (alternate/fallback WMI provider)
github.com/buger/jsonparser v1.1.1 Fast JSON parsing for exfil

^[strings-unpacked.txt:6958–6975]

Notable functions:

  • main.(*wsSess).recvWss, main.(*wsSess).sendTrace, main.(*wsSess).Start — WebSocket session management (C2 channel). ^[strings-unpacked.txt:20088–20118]
  • main.(*wsSess).execCommand, main.(*wsSess).sepDesktop, main.(*wsSess).ffdesktop — remote command execution and desktop separation (likely RDP / screen sharing / multi-desktop isolation for evasion). ^[strings-unpacked.txt:20119–20123]
  • main.base64decode — config/blob decoding. ^[strings-unpacked.txt:20082]
  • main.GetHWID — machine fingerprinting. ^[strings-unpacked.txt:20205]
  • salat/screenshot.Capture, salat/screenshot.CaptureRect — screen capture. ^[strings-unpacked.txt:16202–16213]

2. Deploy / ATT&CK

TTPs (static + sibling inference):

  • T1555.003 — Credentials from Web Browsers: Chromium + Gecko cookie/SQLite DB parsing via ncruces/go-sqlite3; DPAPI/AES key recovery (CANT DECRYPT KEY, AES ERROR). ^[strings-unpacked.txt:4751]
  • T1082 — System Information Discovery: GetHWID, WMI queries, PC Name:, OS:, IP:, Resolution:. ^[strings-unpacked.txt:4729]
  • T1056.001 — Input Capture / Keylogging: GetKeyboardState, GetLastInputInfo, GetClipboardData, Active window: strings. ^[strings-unpacked.txt:4751]
  • T1113 — Screen Capture: salat/screenshot.CaptureRect. ^[strings-unpacked.txt:16203]
  • T1115 — Clipboard Data: clipboard-hijack implied by clipboard API imports and stealer family behaviour.
  • T1071 — Application Layer Protocol: QUIC/HTTP3 primary (quic-go v0.38.1), WebSocket fallback (gorilla/websocket), HTTP/2.0 and HTTP/1.1 fallbacks. ^[strings-unpacked.txt:4734]
  • T1572 — Protocol Tunneling: DNS-over-HTTPS fallback (https://1.1.1.1/dns-query, https://cloudflare-dns.com/dns-query, https://dns.google/resolve). ^[strings-unpacked.txt:4784]
  • T1543.005 — Create or Modify System Process (Task Scheduler): capnspacehook/taskmaster. ^[strings-unpacked.txt:6961]
  • T1567 — Exfiltration Over Web Service: JSON POST (application/json), LOG SENT!, steal finished!. ^[strings-unpacked.txt:4729]
  • T1083 — File and Directory Discovery: browser profile enumeration, wallet path traversal.

Persistence: Windows Task Scheduler via OLE automation (taskmaster). No registry Run key observed in strings (unlike some stealer families).

C2 / Exfil:

  • Primary: WebSocket-over-TLS (wsSess struct, gorilla/websocket), with QUIC/HTTP3 as the preferred high-performance transport (quic-go).
  • Fallback: DoH (Cloudflare, Google, Quad9) for name resolution if direct C2 is blocked.
  • Exfil format: application/json POSTs. No hardcoded Telegram bot token or Discord webhook URL found in static strings; config is likely delivered via the C2 WebSocket at runtime.
  • No static C2 endpoint, IP, or domain recovered from unpacked binary. dQw4w9WgXcQ (Rickroll YouTube ID) present in strings — likely placeholder or test artifact. ^[strings-unpacked.txt:4748]

Attribution:

  • Russian-language builder/distribution context (AFK Stealer sold on Russian-speaking cybercrime forums).
  • Version string [AFK] 0.28.1 (x86) is consistent across all three siblings.
  • No code-signing or branding beyond the version banner.

3. Sibling Comparison

Attribute b07d5dcd (this) 0b6c65cd 6d8ecdd1
Version 0.28.1 0.28.1 0.28.1
Go version 1.24.0 1.24.0 1.24.0
Module salat salat salat
Architecture x86 x86 x86
Packing UPX UPX UPX
Dep graph Identical Identical Identical
Strings (unpacked) 22,858 21,900 (approx) ~21,900
Unique delta None — byte-level build variation — —

All three siblings share an identical dependency graph, version banner, module name, and build configuration. No functional deltas detected in static surface. Likely successive builds from the same builder with minor code or config changes between compiles.

4. IOCs

Type Value Note
Version banner [AFK] 0.28.1 (x86) Present in all siblings
Go module salat (devel) Build path: salat
Imphash (packed) N/A (UPX-stripped) No recoverable import table
Rich PE hash N/A Zeroed timestamps
ssdeep See ssdeep.txt Packed-stage only
Network DoH: 1.1.1.1, cloudflare-dns.com, dns.google Static fallback

Static-only analysis. No CAPE runtime data available (empty dynamic-analysis.md / cape-report.json).