typeanalysisfamilyafk-stealerconfidencehighmalware-familyinfostealerratgocredential-theftcrypto-wallet-theftbrowser-theftc2-protocolpersistencedefense-evasiondiscoveryexfiltration
SHA-256: bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade

AFK Stealer: bd6dead7f5a0ec51 — Fourth confirmed sibling, expanded RAT surface

Executive Summary

AFK Stealer (AFKSystems) fourth confirmed sibling. Same version string [AFK] 0.28.1 (x86) and Go 1.24.0 x86 build as the three prior siblings, but not UPX-packed and carrying a massively expanded remote-access surface: WebSocket C2, SOCKS5 proxy pivoting, real-time screen streaming, low-level keylogging, remote shell, webcam/mic capture, hidden desktop sessions, token duplication for privilege escalation, and Chrome App-Bound Encryption bypass. Static-only — CAPE skipped (no Windows guest). ^[file.txt] ^[strings.txt:10854]

What It Is

Field Value
SHA-256 bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade
Size 12,573,696 bytes (11.98 MiB)
Type PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt]
Compiler Go 1.24.0, GOOS=windows, GOARCH=386 ^[strings.txt:15425]
Build ID NICQ78KYzHAmwNqO22OH/R_X2oEpuwKBaSLwMzbgu/gVWbcGQl6mdYA8zQx3XH/8_GEy2Xno8ifRD8nKuVa ^[strings.txt:7]
Packing None — not UPX-packed (unlike siblings 0b6c65cd, 6d8ecdd1, b07d5dcd)
Signing Unsigned ^[rabin2-info.txt:27]
Subsystem Windows GUI ^[rabin2-info.txt:32]
Entry point 0x479370 ^[exiftool.json:22]
.text size 5,247,488 bytes ^[exiftool.json:19]

Six standard PE sections: .text, .rdata, .data, .idata, .reloc, .symtab. ^[pefile.txt:76] The .symtab section is intact with 402 main.* functions (vs ~50 in prior siblings), giving full function-name visibility. ^[strings.txt:29127]

OpenCTI labels: exe, malware-bazaar, upx-dec — the upx-dec label is a false positive inherited from the cluster; this sample is not UPX-packed. ^[triage.json]

How It Works

Entry Point & Runtime

Standard Go runtime entry at 0x479370 (entry0). ^[rabin2-info.txt:22] No anti-debug, no VM detection, no sandbox evasion. The binary is a straightforward Go GUI executable that initializes its runtime, spawns goroutines, and enters the main event loop.

The main.main function spawns at least 8 goroutines (main.main.func1 through main.main.func8, plus main.main.gowrap1/2/3). ^[strings.txt:29286] One of these initializes the C2 connection (main.initConnection), another sets up persistence (main.staticinstall), and others handle task loops and error reporting.

C2 & Communication

Primary transport: WebSocket via github.com/gorilla/websocket. ^[strings.txt:9126] The C2 session is managed by a wsSess type with methods Start, Stop, recvWss, sendTrace, sepDesktop, execCommand, shellCommand, startShell, stopShell, sendShellCommand, p2p, ffdesktop, ffwmic, ffwcam. ^[strings.txt:29134]

Fallback transports:

  • QUIC/HTTP3 via github.com/quic-go/quic-go ^[strings.txt:8923]
  • DNS-over-HTTPS fallback to Cloudflare (https://cloudflare-dns.com/dns-query?name=), Google, and Quad9 (https://1.1.1.1/dns-query?name=) ^[strings.txt:10864] ^[strings.txt:10913]

No hardcoded attacker C2 domain visible in strings — likely runtime-resolved via a config blob, paste site, or embedded Wasm module (the wazero runtime is present). ^[strings.txt:9243]

The binary can also act as a C2 server / SOCKS5 proxy: main.c2Server, main.proxy, main.forward, main.p2pSocks, main.proxySocks, main.(*socks5Conn).Serve. ^[strings.txt:29227] This enables infected hosts to pivot traffic for the attacker.

Persistence

Windows Task Scheduler via github.com/capnspacehook/taskmaster. ^[strings.txt:9572] Functions main.newTask and main.staticinstall create scheduled tasks. ^[strings.txt:29304] This is the same persistence mechanism observed in the three prior siblings.

Information Theft

Browser credential theft is comprehensive and identical in targeting to prior siblings:

Chromium family (Chrome, Edge, Brave, Opera, Yandex, Chedot, Kometa, Fenrir, CocCoc, etc.):

  • main.getChromeLogins, main.getChromeCookies, main.getChromeToken, main.getChromeAutofils ^[strings.txt:29384]
  • DPAPI master key retrieval: main.GetChromiumMasterKeys, main.DecryptChrome ^[strings.txt:29416]
  • Chrome App-Bound Encryption bypass: main.GetAppBoundKey, main.StartAPPB, main.decryptAPPB ^[strings.txt:29449]

Gecko family (Firefox, Thunderbird, Waterfox, SeaMonkey, etc.):

  • main.getGeckoLogins, main.getGeckoCookies ^[strings.txt:29352]
  • NSS master key: main.GetGeckoMasterKey, main.DecryptGecko ^[strings.txt:29396]
  • DES3 + AES-128-CBC decryption of key4.db ^[strings.txt:29402]

Other targets:

  • Discord: main.getDiscord ^[strings.txt:29357]
  • Steam: main.decodeSteam, main.getSteams, main.parseVdf ^[strings.txt:29366]
  • Telegram Desktop: paths to tdata directories ^[strings.txt:10854]
  • TON blockchain: main.decodeFromTonAddress, main.tonResolve ^[strings.txt:29322]
  • Clipboard: main.getClipboardText ^[strings.txt:29249]
  • System info / HWID: main.GetHWID, main.GetHWID2, main.getEp ^[strings.txt:29270]

RAT Surface (New vs. Prior Siblings)

The following capabilities are present in this sibling but absent from the three prior AFK Stealer analyses:

Capability Evidence
WebSocket C2 main.(*wsSess).recvWss, github.com/gorilla/websocket ^[strings.txt:29134]
SOCKS5 proxy pivoting main.p2pSocks, main.proxySocks, main.(*socks5Conn).Serve ^[strings.txt:29213]
Real-time screen streaming main.screenStream, main.sendScreen, salat/screenshot ^[strings.txt:29191]
Keylogging main.startKeylogger, main.runKeylogger, main.SetWinEventHook, main.keyPressCallback ^[strings.txt:29189]
Webcam capture main.getWebcams, main.(*wsSess).ffwcam ^[strings.txt:29199]
Microphone capture main.getMics ^[strings.txt:29200]
Remote shell main.startShell, main.shellCommand, main.sendShellCommand, main.stopShell ^[strings.txt:29182]
Hidden desktop main.(*wsSess).sepDesktop, main.(*wsSess).ffdesktop ^[strings.txt:29170]
Token duplication / privilege escalation main.Elevate, main.impersonateSystem, main.DuplicateUserTokenFromSessionID, main.getSystemToken ^[strings.txt:29442]
Process suspension main.suspendProcessThreads ^[strings.txt:29246]
File download/upload/zip main.downloadFile, main.zipFiles, main.zipAddFS ^[strings.txt:29192]
Self-deletion main.selfDelete, main.Suicide ^[strings.txt:29440]
System idle detection main.IsIdle, main.GetLastInputTime ^[strings.txt:29263]
Lsass process enumeration main.findLsassProcess ^[strings.txt:29418]

Privilege Escalation

The binary includes a full token-duplication path for UAC bypass and privilege escalation:

  • main.isAdmin checks elevation status ^[strings.txt:29276]
  • main.enablePrivilege enables specific privileges ^[strings.txt:29417]
  • main.getSystemToken obtains a SYSTEM token ^[strings.txt:29420]
  • main.impersonateSystem impersonates SYSTEM ^[strings.txt:29422]
  • main.DuplicateUserTokenFromSessionID duplicates tokens across sessions ^[strings.txt:29244]
  • main.Elevate is the top-level escalation routine ^[strings.txt:29442]

This suggests the stealer can self-elevate to access protected browser credential stores (Chrome App-Bound keys, elevated Firefox profiles) and to enable the remote shell / keylogger to run with higher privileges.

Decompiled Behavior

Ghidra load attempted but analysis timed out on the 12.5 MB binary. radare2 level-1 analysis completed (10,560 functions). Entry point entry0 at 0x479370 is standard Go runtime initialization: CPUID check for MMX, TLS allocation, runtime.main dispatch. ^[r2:entry0]

No control-flow flattening, no string encryption, no anti-disassembly. The binary is a standard Go compile with -ldflags="-s -w" (stripped but .symtab retained). Function names are unobfuscated, making static analysis straightforward.

C2 Infrastructure

Indicator Value Notes
Primary C2 WebSocket (wss://) gorilla/websocket library, wsSess type
Fallback C2 QUIC/HTTP3 quic-go library present
DNS fallback DoH Cloudflare, Google, Quad9 hardcoded
C2 config Runtime-resolved No hardcoded attacker domain in strings
Exfil format application/json application/json string present ^[strings.txt:10878]
Confirmation steal finished! Exfil confirmation string ^[strings.txt:10877]

No IP addresses, domains, or paste-site URLs were recovered from static strings. The C2 endpoint is likely delivered via:

  • An embedded/configured WebSocket URL in a resource section or compressed blob
  • A paste-site fetch at runtime (common in Go stealers)
  • A Wasm module loaded via wazero

The wazero Wasm runtime (github.com/tetratelabs/wazero) is present with full API (wazero.Runtime, wazero.RuntimeConfig, wazero.ModuleConfig). ^[strings.txt:6479] This may be used for plugin loading or config decoding.

Interesting Tidbits

  • Builder modularity: The identical version string 0.28.1 across a ~50-function UPX-packed infostealer and a 402-function non-packed RAT suggests a single builder with feature flags. The builder can toggle RAT modules on/off.
  • Package name leak: salat/main.go and salat/screenshot appear in strings, suggesting the Go module path is salat or a fork of the salat/screenshot library. ^[strings.txt:30584]
  • No UPX: This sibling skips UPX entirely. The 12.5 MB size is raw Go binary + embedded dependencies. This may be a deliberate choice to avoid UPX-detection signatures.
  • App-Bound Encryption bypass: The inclusion of GetAppBoundKey, StartAPPB, and decryptAPPB functions shows the author is actively tracking Chrome's evolving credential protection. This is a relatively recent technique (Chrome 114+).
  • TON blockchain support: tonutils-go is present with address decoding and TVM cell parsing. ^[strings.txt:9732] This targets TON (The Open Network) wallets, a less-common target in commodity stealers.
  • Rickroll easter egg: The string dQw4w9WgXcQ (the YouTube ID for "Never Gonna Give You Up") appears in the binary. ^[strings.txt:10864] Either a developer joke or a placeholder/test value.
  • MachineGuid paths: The binary references C:\Windows\System32\restore\MachineGuid.txt, C:\Windows\SysWOW64\restore\MachineGuid.txt, and C:\Windows\Sysnative\restore\MachineGuid.txt — unusual paths for MachineGuid retrieval, possibly evasion or fallback logic. ^[strings.txt:10930]

How To Mess With It (Homelab Replication)

Toolchain: Go 1.24.0, Windows 386 target, CGO_ENABLED=0

Dependencies to reproduce the build fingerprint:

github.com/quic-go/quic-go v0.48.x
github.com/gorilla/websocket v1.5.x
github.com/capnspacehook/taskmaster v1.x
github.com/tetratelabs/wazero v1.x
github.com/ncruces/go-sqlite3 v0.x
github.com/xssnick/tonutils-go v1.x
github.com/lxn/win v0.x
github.com/yusufpapurcu/wmi v1.x
github.com/andygrunwald/vdf v1.x
github.com/nfnt/resize v0.x
golang.org/x/crypto v0.32.x

Build flags (inferred from strings):

GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -ldflags="-s -w" -trimpath .

Verification: Run strings on the output and grep for go1.24.0, github.com/quic-go/quic-go, github.com/gorilla/websocket, and github.com/capnspacehook/taskmaster. A comparable binary should show all four module paths.

Deployable Signatures

YARA Rule

rule afk_stealer_rat_2026 {
    meta:
        description = "AFK Stealer / RAT - Go-based infostealer and remote access tool"
        author = "PacketPursuit"
        date = "2026-08-18"
        hash = "bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade"
        family = "afk-stealer"
        confidence = "high"
    
    strings:
        $afk_ver = "[AFK] 0.28.1 (x86)" ascii wide
        $salat = "salat/screenshot" ascii wide
        $wsSess = "main.(*wsSess)" ascii wide
        $gorilla_ws = "github.com/gorilla/websocket" ascii wide
        $quic_go = "github.com/quic-go/quic-go" ascii wide
        $taskmaster = "github.com/capnspacehook/taskmaster" ascii wide
        $wazero = "github.com/tetratelabs/wazero" ascii wide
        $sqlite3 = "github.com/ncruces/go-sqlite3" ascii wide
        $tonutils = "github.com/xssnick/tonutils-go" ascii wide
        $go_build = "go1.24.0" ascii wide
        $p2pSocks = "main.p2pSocks" ascii wide
        $c2Server = "main.c2Server" ascii wide
        $screenStream = "main.screenStream" ascii wide
        $startKeylogger = "main.startKeylogger" ascii wide
        $elevate = "main.Elevate" ascii wide
        $appbound = "main.GetAppBoundKey" ascii wide
    
    condition:
        uint16(0) == 0x5A4D and
        $afk_ver and
        4 of ($gorilla_ws, $quic_go, $taskmaster, $wazero, $sqlite3, $tonutils) and
        2 of ($p2pSocks, $c2Server, $screenStream, $startKeylogger, $elevate, $appbound, $wsSess)
}

Behavioral Fingerprint

Go-compiled PE32 (x86) executable, 10–13 MB, GUI subsystem, no visible window. On execution, spawns multiple goroutines including WebSocket client loops (main.(*wsSess).recvWss), Task Scheduler persistence tasks (main.newTask), and browser credential harvesting threads (main.Steal, main.getChromeLogins, main.getGeckoLogins). Enumerates 15+ browser profile paths under %LOCALAPPDATA% and %APPDATA%, accesses Chrome Local State and Login Data SQLite databases, and attempts DPAPI / App-Bound key decryption (main.GetAppBoundKey, main.DPAPI). May create hidden desktop sessions (main.(*wsSess).sepDesktop) and start SOCKS5 proxy listeners on ephemeral ports (main.p2pSocks, main.proxySocks). Exfiltrates via WebSocket or QUIC/HTTP3 to runtime-resolved endpoints, with DNS-over-HTTPS fallback to Cloudflare/Google/Quad9. Self-deletes on command (main.selfDelete, main.Suicide).

IOC List

IOC Type Value
SHA-256 Hash bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade
ssdeep Hash 98304:M5L+G8grxcCqRUmIBFbU/b6L49433HNHXEmO/:lGtQRUmIBl0b4Ws0mO/ ^[triage.json]
Version string String [AFK] 0.28.1 (x86)
Go build ID String NICQ78KYzHAmwNqO22OH/R_X2oEpuwKBaSLwMzbgu/gVWbcGQl6mdYA8zQx3XH/8_GEy2Xno8ifRD8nKuVa
Package path String salat/screenshot
DoH endpoint URL https://cloudflare-dns.com/dns-query?name=
DoH endpoint URL https://1.1.1.1/dns-query?name=
Registry persistence Registry SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run ^[strings.txt:10930]
MachineGuid path File path C:\\Windows\\System32\\restore\\MachineGuid.txt
Telegram data File path Telegram Desktop UWP\\tdata ^[strings.txt:10854]
Discord token File path $appdata\\discord ^[strings.txt:10877]
Steam config File path AccountId-config.vdf ^[strings.txt:10864]
Browser targets File path BraveSoftware, Chrome, Edge, Opera, Yandex, Firefox, Thunderbird, SeaMonkey, CocCoc, Chedot, Kometa, Fenrir
Wallet targets String Exodus, Armory, Guarda, MetaMask, TonKeeper, AtomicWallet, Trust Wallet, Jaxx Liberty, Electrum, MyMonero, Coinbase, Phantom, SafePal, XMR.PT

Detection Signatures

MITRE ATT&CK Mapping:

Technique ID Evidence
Credentials from Web Browsers T1555.003 main.getChromeLogins, main.getGeckoLogins, main.DecryptChrome, main.DecryptGecko
Screen Capture T1113 main.screenStream, main.sendScreen, salat/screenshot
Clipboard Data T1115 main.getClipboardText
System Information Discovery T1082 main.GetHWID, main.getDevices, main.getDrives
Create or Modify System Process T1543.003 main.newTask, github.com/capnspacehook/taskmaster
Application Layer Protocol: WebSocket T1071.001 github.com/gorilla/websocket, main.(*wsSess).recvWss
Protocol Tunneling T1572 QUIC/HTTP3, DoH fallback
Exfiltration Over Web Service T1567 application/json, steal finished!
File and Directory Discovery T1083 main.getDrives, main.getRandomFolders
Input Capture: Keylogging T1056.001 main.startKeylogger, main.runKeylogger, main.SetWinEventHook
Windows Command Shell T1059.003 main.startShell, main.shellCommand
Proxy T1090 main.p2pSocks, main.proxySocks, main.c2Server
DNS-over-HTTPS T1071.004 https://cloudflare-dns.com/dns-query?name=
Access Token Manipulation T1134.001 main.DuplicateUserTokenFromSessionID, main.impersonateSystem
Bypass User Access Control T1548.002 main.Elevate, main.enablePrivilege
Process Discovery T1057 main.processes, main.findProcessByName
Hide Artifacts: Hidden Desktop T1564.011 main.(*wsSess).sepDesktop, main.(*wsSess).ffdesktop
Indicator Removal: File Deletion T1070.004 main.selfDelete, main.Suicide

References

Provenance

Static analysis performed 2026-08-18 on pp-hermes (Linux 6.14.8-2-pve). Tools: file (PE32), exiftool 12.76, pefile (6 sections, import table), strings (1816249 chars, 37790 lines), floss (failed — argument parsing error), capa (failed — missing signatures), binwalk (embedded SQLite, LZMA, mcrypt, AES S-Box signatures), radare2 (level-1 analysis, 10560 functions, entry0 decompile), Ghidra (load attempted, analysis timed out). CAPE sandbox skipped — no Windows guest available. ^[dynamic-analysis.md]