bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1adeAFK Stealer: bd6dead7f5a0ec51 — Fourth confirmed sibling, expanded RAT surface
Executive Summary
AFK Stealer (AFKSystems) fourth confirmed sibling. Same version string [AFK] 0.28.1 (x86) and Go 1.24.0 x86 build as the three prior siblings, but not UPX-packed and carrying a massively expanded remote-access surface: WebSocket C2, SOCKS5 proxy pivoting, real-time screen streaming, low-level keylogging, remote shell, webcam/mic capture, hidden desktop sessions, token duplication for privilege escalation, and Chrome App-Bound Encryption bypass. Static-only — CAPE skipped (no Windows guest). ^[file.txt] ^[strings.txt:10854]
What It Is
| Field | Value |
|---|---|
| SHA-256 | bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade |
| Size | 12,573,696 bytes (11.98 MiB) |
| Type | PE32 executable (GUI) Intel 80386, 6 sections ^[file.txt] |
| Compiler | Go 1.24.0, GOOS=windows, GOARCH=386 ^[strings.txt:15425] |
| Build ID | NICQ78KYzHAmwNqO22OH/R_X2oEpuwKBaSLwMzbgu/gVWbcGQl6mdYA8zQx3XH/8_GEy2Xno8ifRD8nKuVa ^[strings.txt:7] |
| Packing | None — not UPX-packed (unlike siblings 0b6c65cd, 6d8ecdd1, b07d5dcd) |
| Signing | Unsigned ^[rabin2-info.txt:27] |
| Subsystem | Windows GUI ^[rabin2-info.txt:32] |
| Entry point | 0x479370 ^[exiftool.json:22] |
.text size |
5,247,488 bytes ^[exiftool.json:19] |
Six standard PE sections: .text, .rdata, .data, .idata, .reloc, .symtab. ^[pefile.txt:76] The .symtab section is intact with 402 main.* functions (vs ~50 in prior siblings), giving full function-name visibility. ^[strings.txt:29127]
OpenCTI labels: exe, malware-bazaar, upx-dec — the upx-dec label is a false positive inherited from the cluster; this sample is not UPX-packed. ^[triage.json]
How It Works
Entry Point & Runtime
Standard Go runtime entry at 0x479370 (entry0). ^[rabin2-info.txt:22] No anti-debug, no VM detection, no sandbox evasion. The binary is a straightforward Go GUI executable that initializes its runtime, spawns goroutines, and enters the main event loop.
The main.main function spawns at least 8 goroutines (main.main.func1 through main.main.func8, plus main.main.gowrap1/2/3). ^[strings.txt:29286] One of these initializes the C2 connection (main.initConnection), another sets up persistence (main.staticinstall), and others handle task loops and error reporting.
C2 & Communication
Primary transport: WebSocket via github.com/gorilla/websocket. ^[strings.txt:9126] The C2 session is managed by a wsSess type with methods Start, Stop, recvWss, sendTrace, sepDesktop, execCommand, shellCommand, startShell, stopShell, sendShellCommand, p2p, ffdesktop, ffwmic, ffwcam. ^[strings.txt:29134]
Fallback transports:
- QUIC/HTTP3 via
github.com/quic-go/quic-go^[strings.txt:8923] - DNS-over-HTTPS fallback to Cloudflare (
https://cloudflare-dns.com/dns-query?name=), Google, and Quad9 (https://1.1.1.1/dns-query?name=) ^[strings.txt:10864] ^[strings.txt:10913]
No hardcoded attacker C2 domain visible in strings — likely runtime-resolved via a config blob, paste site, or embedded Wasm module (the wazero runtime is present). ^[strings.txt:9243]
The binary can also act as a C2 server / SOCKS5 proxy: main.c2Server, main.proxy, main.forward, main.p2pSocks, main.proxySocks, main.(*socks5Conn).Serve. ^[strings.txt:29227] This enables infected hosts to pivot traffic for the attacker.
Persistence
Windows Task Scheduler via github.com/capnspacehook/taskmaster. ^[strings.txt:9572] Functions main.newTask and main.staticinstall create scheduled tasks. ^[strings.txt:29304] This is the same persistence mechanism observed in the three prior siblings.
Information Theft
Browser credential theft is comprehensive and identical in targeting to prior siblings:
Chromium family (Chrome, Edge, Brave, Opera, Yandex, Chedot, Kometa, Fenrir, CocCoc, etc.):
main.getChromeLogins,main.getChromeCookies,main.getChromeToken,main.getChromeAutofils^[strings.txt:29384]- DPAPI master key retrieval:
main.GetChromiumMasterKeys,main.DecryptChrome^[strings.txt:29416] - Chrome App-Bound Encryption bypass:
main.GetAppBoundKey,main.StartAPPB,main.decryptAPPB^[strings.txt:29449]
Gecko family (Firefox, Thunderbird, Waterfox, SeaMonkey, etc.):
main.getGeckoLogins,main.getGeckoCookies^[strings.txt:29352]- NSS master key:
main.GetGeckoMasterKey,main.DecryptGecko^[strings.txt:29396] - DES3 + AES-128-CBC decryption of
key4.db^[strings.txt:29402]
Other targets:
- Discord:
main.getDiscord^[strings.txt:29357] - Steam:
main.decodeSteam,main.getSteams,main.parseVdf^[strings.txt:29366] - Telegram Desktop: paths to
tdatadirectories ^[strings.txt:10854] - TON blockchain:
main.decodeFromTonAddress,main.tonResolve^[strings.txt:29322] - Clipboard:
main.getClipboardText^[strings.txt:29249] - System info / HWID:
main.GetHWID,main.GetHWID2,main.getEp^[strings.txt:29270]
RAT Surface (New vs. Prior Siblings)
The following capabilities are present in this sibling but absent from the three prior AFK Stealer analyses:
| Capability | Evidence |
|---|---|
| WebSocket C2 | main.(*wsSess).recvWss, github.com/gorilla/websocket ^[strings.txt:29134] |
| SOCKS5 proxy pivoting | main.p2pSocks, main.proxySocks, main.(*socks5Conn).Serve ^[strings.txt:29213] |
| Real-time screen streaming | main.screenStream, main.sendScreen, salat/screenshot ^[strings.txt:29191] |
| Keylogging | main.startKeylogger, main.runKeylogger, main.SetWinEventHook, main.keyPressCallback ^[strings.txt:29189] |
| Webcam capture | main.getWebcams, main.(*wsSess).ffwcam ^[strings.txt:29199] |
| Microphone capture | main.getMics ^[strings.txt:29200] |
| Remote shell | main.startShell, main.shellCommand, main.sendShellCommand, main.stopShell ^[strings.txt:29182] |
| Hidden desktop | main.(*wsSess).sepDesktop, main.(*wsSess).ffdesktop ^[strings.txt:29170] |
| Token duplication / privilege escalation | main.Elevate, main.impersonateSystem, main.DuplicateUserTokenFromSessionID, main.getSystemToken ^[strings.txt:29442] |
| Process suspension | main.suspendProcessThreads ^[strings.txt:29246] |
| File download/upload/zip | main.downloadFile, main.zipFiles, main.zipAddFS ^[strings.txt:29192] |
| Self-deletion | main.selfDelete, main.Suicide ^[strings.txt:29440] |
| System idle detection | main.IsIdle, main.GetLastInputTime ^[strings.txt:29263] |
| Lsass process enumeration | main.findLsassProcess ^[strings.txt:29418] |
Privilege Escalation
The binary includes a full token-duplication path for UAC bypass and privilege escalation:
main.isAdminchecks elevation status ^[strings.txt:29276]main.enablePrivilegeenables specific privileges ^[strings.txt:29417]main.getSystemTokenobtains a SYSTEM token ^[strings.txt:29420]main.impersonateSystemimpersonates SYSTEM ^[strings.txt:29422]main.DuplicateUserTokenFromSessionIDduplicates tokens across sessions ^[strings.txt:29244]main.Elevateis the top-level escalation routine ^[strings.txt:29442]
This suggests the stealer can self-elevate to access protected browser credential stores (Chrome App-Bound keys, elevated Firefox profiles) and to enable the remote shell / keylogger to run with higher privileges.
Decompiled Behavior
Ghidra load attempted but analysis timed out on the 12.5 MB binary. radare2 level-1 analysis completed (10,560 functions). Entry point entry0 at 0x479370 is standard Go runtime initialization: CPUID check for MMX, TLS allocation, runtime.main dispatch. ^[r2:entry0]
No control-flow flattening, no string encryption, no anti-disassembly. The binary is a standard Go compile with -ldflags="-s -w" (stripped but .symtab retained). Function names are unobfuscated, making static analysis straightforward.
C2 Infrastructure
| Indicator | Value | Notes |
|---|---|---|
| Primary C2 | WebSocket (wss://) | gorilla/websocket library, wsSess type |
| Fallback C2 | QUIC/HTTP3 | quic-go library present |
| DNS fallback | DoH | Cloudflare, Google, Quad9 hardcoded |
| C2 config | Runtime-resolved | No hardcoded attacker domain in strings |
| Exfil format | application/json |
application/json string present ^[strings.txt:10878] |
| Confirmation | steal finished! |
Exfil confirmation string ^[strings.txt:10877] |
No IP addresses, domains, or paste-site URLs were recovered from static strings. The C2 endpoint is likely delivered via:
- An embedded/configured WebSocket URL in a resource section or compressed blob
- A paste-site fetch at runtime (common in Go stealers)
- A Wasm module loaded via
wazero
The wazero Wasm runtime (github.com/tetratelabs/wazero) is present with full API (wazero.Runtime, wazero.RuntimeConfig, wazero.ModuleConfig). ^[strings.txt:6479] This may be used for plugin loading or config decoding.
Interesting Tidbits
- Builder modularity: The identical version string
0.28.1across a ~50-function UPX-packed infostealer and a 402-function non-packed RAT suggests a single builder with feature flags. The builder can toggle RAT modules on/off. - Package name leak:
salat/main.goandsalat/screenshotappear in strings, suggesting the Go module path issalator a fork of thesalat/screenshotlibrary. ^[strings.txt:30584] - No UPX: This sibling skips UPX entirely. The 12.5 MB size is raw Go binary + embedded dependencies. This may be a deliberate choice to avoid UPX-detection signatures.
- App-Bound Encryption bypass: The inclusion of
GetAppBoundKey,StartAPPB, anddecryptAPPBfunctions shows the author is actively tracking Chrome's evolving credential protection. This is a relatively recent technique (Chrome 114+). - TON blockchain support:
tonutils-gois present with address decoding and TVM cell parsing. ^[strings.txt:9732] This targets TON (The Open Network) wallets, a less-common target in commodity stealers. - Rickroll easter egg: The string
dQw4w9WgXcQ(the YouTube ID for "Never Gonna Give You Up") appears in the binary. ^[strings.txt:10864] Either a developer joke or a placeholder/test value. - MachineGuid paths: The binary references
C:\Windows\System32\restore\MachineGuid.txt,C:\Windows\SysWOW64\restore\MachineGuid.txt, andC:\Windows\Sysnative\restore\MachineGuid.txt— unusual paths for MachineGuid retrieval, possibly evasion or fallback logic. ^[strings.txt:10930]
How To Mess With It (Homelab Replication)
Toolchain: Go 1.24.0, Windows 386 target, CGO_ENABLED=0
Dependencies to reproduce the build fingerprint:
github.com/quic-go/quic-go v0.48.x
github.com/gorilla/websocket v1.5.x
github.com/capnspacehook/taskmaster v1.x
github.com/tetratelabs/wazero v1.x
github.com/ncruces/go-sqlite3 v0.x
github.com/xssnick/tonutils-go v1.x
github.com/lxn/win v0.x
github.com/yusufpapurcu/wmi v1.x
github.com/andygrunwald/vdf v1.x
github.com/nfnt/resize v0.x
golang.org/x/crypto v0.32.x
Build flags (inferred from strings):
GOOS=windows GOARCH=386 CGO_ENABLED=0 go build -ldflags="-s -w" -trimpath .
Verification: Run strings on the output and grep for go1.24.0, github.com/quic-go/quic-go, github.com/gorilla/websocket, and github.com/capnspacehook/taskmaster. A comparable binary should show all four module paths.
Deployable Signatures
YARA Rule
rule afk_stealer_rat_2026 {
meta:
description = "AFK Stealer / RAT - Go-based infostealer and remote access tool"
author = "PacketPursuit"
date = "2026-08-18"
hash = "bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade"
family = "afk-stealer"
confidence = "high"
strings:
$afk_ver = "[AFK] 0.28.1 (x86)" ascii wide
$salat = "salat/screenshot" ascii wide
$wsSess = "main.(*wsSess)" ascii wide
$gorilla_ws = "github.com/gorilla/websocket" ascii wide
$quic_go = "github.com/quic-go/quic-go" ascii wide
$taskmaster = "github.com/capnspacehook/taskmaster" ascii wide
$wazero = "github.com/tetratelabs/wazero" ascii wide
$sqlite3 = "github.com/ncruces/go-sqlite3" ascii wide
$tonutils = "github.com/xssnick/tonutils-go" ascii wide
$go_build = "go1.24.0" ascii wide
$p2pSocks = "main.p2pSocks" ascii wide
$c2Server = "main.c2Server" ascii wide
$screenStream = "main.screenStream" ascii wide
$startKeylogger = "main.startKeylogger" ascii wide
$elevate = "main.Elevate" ascii wide
$appbound = "main.GetAppBoundKey" ascii wide
condition:
uint16(0) == 0x5A4D and
$afk_ver and
4 of ($gorilla_ws, $quic_go, $taskmaster, $wazero, $sqlite3, $tonutils) and
2 of ($p2pSocks, $c2Server, $screenStream, $startKeylogger, $elevate, $appbound, $wsSess)
}
Behavioral Fingerprint
Go-compiled PE32 (x86) executable, 10–13 MB, GUI subsystem, no visible window. On execution, spawns multiple goroutines including WebSocket client loops (main.(*wsSess).recvWss), Task Scheduler persistence tasks (main.newTask), and browser credential harvesting threads (main.Steal, main.getChromeLogins, main.getGeckoLogins). Enumerates 15+ browser profile paths under %LOCALAPPDATA% and %APPDATA%, accesses Chrome Local State and Login Data SQLite databases, and attempts DPAPI / App-Bound key decryption (main.GetAppBoundKey, main.DPAPI). May create hidden desktop sessions (main.(*wsSess).sepDesktop) and start SOCKS5 proxy listeners on ephemeral ports (main.p2pSocks, main.proxySocks). Exfiltrates via WebSocket or QUIC/HTTP3 to runtime-resolved endpoints, with DNS-over-HTTPS fallback to Cloudflare/Google/Quad9. Self-deletes on command (main.selfDelete, main.Suicide).
IOC List
| IOC | Type | Value |
|---|---|---|
| SHA-256 | Hash | bd6dead7f5a0ec516608de8ad004564e6df2dad24549536739283f44cfde1ade |
| ssdeep | Hash | 98304:M5L+G8grxcCqRUmIBFbU/b6L49433HNHXEmO/:lGtQRUmIBl0b4Ws0mO/ ^[triage.json] |
| Version string | String | [AFK] 0.28.1 (x86) |
| Go build ID | String | NICQ78KYzHAmwNqO22OH/R_X2oEpuwKBaSLwMzbgu/gVWbcGQl6mdYA8zQx3XH/8_GEy2Xno8ifRD8nKuVa |
| Package path | String | salat/screenshot |
| DoH endpoint | URL | https://cloudflare-dns.com/dns-query?name= |
| DoH endpoint | URL | https://1.1.1.1/dns-query?name= |
| Registry persistence | Registry | SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run ^[strings.txt:10930] |
| MachineGuid path | File path | C:\\Windows\\System32\\restore\\MachineGuid.txt |
| Telegram data | File path | Telegram Desktop UWP\\tdata ^[strings.txt:10854] |
| Discord token | File path | $appdata\\discord ^[strings.txt:10877] |
| Steam config | File path | AccountId-config.vdf ^[strings.txt:10864] |
| Browser targets | File path | BraveSoftware, Chrome, Edge, Opera, Yandex, Firefox, Thunderbird, SeaMonkey, CocCoc, Chedot, Kometa, Fenrir |
| Wallet targets | String | Exodus, Armory, Guarda, MetaMask, TonKeeper, AtomicWallet, Trust Wallet, Jaxx Liberty, Electrum, MyMonero, Coinbase, Phantom, SafePal, XMR.PT |
Detection Signatures
MITRE ATT&CK Mapping:
| Technique | ID | Evidence |
|---|---|---|
| Credentials from Web Browsers | T1555.003 | main.getChromeLogins, main.getGeckoLogins, main.DecryptChrome, main.DecryptGecko |
| Screen Capture | T1113 | main.screenStream, main.sendScreen, salat/screenshot |
| Clipboard Data | T1115 | main.getClipboardText |
| System Information Discovery | T1082 | main.GetHWID, main.getDevices, main.getDrives |
| Create or Modify System Process | T1543.003 | main.newTask, github.com/capnspacehook/taskmaster |
| Application Layer Protocol: WebSocket | T1071.001 | github.com/gorilla/websocket, main.(*wsSess).recvWss |
| Protocol Tunneling | T1572 | QUIC/HTTP3, DoH fallback |
| Exfiltration Over Web Service | T1567 | application/json, steal finished! |
| File and Directory Discovery | T1083 | main.getDrives, main.getRandomFolders |
| Input Capture: Keylogging | T1056.001 | main.startKeylogger, main.runKeylogger, main.SetWinEventHook |
| Windows Command Shell | T1059.003 | main.startShell, main.shellCommand |
| Proxy | T1090 | main.p2pSocks, main.proxySocks, main.c2Server |
| DNS-over-HTTPS | T1071.004 | https://cloudflare-dns.com/dns-query?name= |
| Access Token Manipulation | T1134.001 | main.DuplicateUserTokenFromSessionID, main.impersonateSystem |
| Bypass User Access Control | T1548.002 | main.Elevate, main.enablePrivilege |
| Process Discovery | T1057 | main.processes, main.findProcessByName |
| Hide Artifacts: Hidden Desktop | T1564.011 | main.(*wsSess).sepDesktop, main.(*wsSess).ffdesktop |
| Indicator Removal: File Deletion | T1070.004 | main.selfDelete, main.Suicide |
References
- Sibling analyses: afk-stealer entity page (siblings
0b6c65cd,6d8ecdd1,b07d5dcd) - Build pattern: golang-stealer-build-pattern
- Browser credential theft: browser-credential-harvesting
- QUIC/HTTP3 C2: quic-http3-c2-transport
- WebSocket C2: websocket-c2-transport
- SOCKS5 proxy pivoting: socks5-proxy-pivoting
- Task Scheduler persistence: task-scheduler-persistence
- DoH fallback: dns-over-https-fallback
- Wasm runtime: wasm-in-process-loader
- Token duplication: token-duplication-privilege-escalation
- App-Bound bypass: app-bound-encryption-bypass
- Clipboard hijacking: clipboard-hijack-cryptocurrency
- RAT concept: rat
Provenance
Static analysis performed 2026-08-18 on pp-hermes (Linux 6.14.8-2-pve). Tools: file (PE32), exiftool 12.76, pefile (6 sections, import table), strings (1816249 chars, 37790 lines), floss (failed — argument parsing error), capa (failed — missing signatures), binwalk (embedded SQLite, LZMA, mcrypt, AES S-Box signatures), radare2 (level-1 analysis, 10560 functions, entry0 decompile), Ghidra (load attempted, analysis timed out). CAPE sandbox skipped — no Windows guest available. ^[dynamic-analysis.md]