typeentityconfidencehighcreated2026-08-15updated2026-08-18malware-familyinfostealerratgocredential-theftcrypto-wallet-theftbrowser-theft

AFK Stealer

Overview

AFK Stealer (also AFKSystems) is a commodity Go-based information stealer sold on Russian-speaking cybercrime forums. Four confirmed siblings: 0b6c65cd, 6d8ecdd1, b07d5dcd, and bd6dead7 (this analysis). It targets browser credentials, cryptocurrency wallets, system information, and clipboard data. Version string [AFK] 0.28.1 (x86) is present in plaintext in observed samples. The fourth sibling (bd6dead7) adds a full RAT surface: WebSocket C2, SOCKS5 proxy pivoting, screen streaming, keylogging, remote shell, webcam/mic capture, hidden desktop, and token-duplication privilege escalation. ^[sample 0b6c65cd/strings-unpacked.txt:10854] ^[sample bd6dead7/strings.txt:10854]

Build Pattern

  • Compiler: Go 1.24.0, GOOS=windows, GOARCH=386 (x86) ^[sample 0b6c65cd/file.txt] ^[sample bd6dead7/strings.txt:15425]
  • Packing: UPX 3.96 in siblings 0b6c65cd, 6d8ecdd1, b07d5dcd; not UPX-packed in sibling bd6dead7 (12.5 MB raw). ^[sample bd6dead7/triage.json]
  • Signing: Unsigned.
  • Obfuscation: Stripped but retains Go .symtab function names (no randomized names observed in this build). No debug checks or VM detection.
  • Resources: No .rsrc, no version info, no icon. GUI subsystem with no visible window code.

Dependencies (Go Modules)

The sample embeds an unusually rich dependency graph for a stealer:

Module Purpose
github.com/quic-go/quic-go QUIC/HTTP3 C2 transport with TLS 1.3 and 0-RTT
github.com/gorilla/websocket WebSocket C2 transport (RAT sibling bd6dead7 only) ^[sample bd6dead7/strings.txt:9126]
github.com/tetratelabs/wazero WebAssembly runtime for in-process plugin/module loading
github.com/capnspacehook/taskmaster Windows Task Scheduler OLE automation for persistence
github.com/ncruces/go-sqlite3 SQLite driver for browser credential database parsing
github.com/xssnick/tonutils-go TON blockchain address/wallet operations
golang.org/x/crypto ML-KEM768, X25519, ChaCha20-Poly1305

^[sample 0b6c65cd/strings-unpacked.txt:4052]

Targets

Browsers (15+)

Chrome, Edge, Brave, Opera, Opera GX, Firefox, Thunderbird, Yandex, SeaMonkey, Comodo Dragon, CocCoc, 360Browser, UR Browser, CentBrowser, Epic Privacy Browser, and others. ^[sample 0b6c65cd/strings-unpacked.txt:10854]

Crypto Wallets (40+)

Exodus, Armory, Guarda, MetaMask, TonKeeper, SuiWallet, AtomicWallet, Trust Wallet, Jaxx Liberty, TerraStation, Electrum, MyMonero, Coinbase, XMR.PT, Phantom, SafePal, Solfare, Enkrypt, and many more. ^[sample 0b6c65cd/strings-unpacked.txt:10854]

Other Targets

  • Telegram Desktop (tdatab paths)
  • Steam (local.vdf)
  • System clipboard (clipboard hijacking)
  • MachineGuid

C2 / Exfiltration

  • Primary: QUIC/HTTP3 via quic-go (TLS 1.3, X25519+MLKEM768, 0-RTT) ^[sample 0b6c65cd/strings-unpacked.txt:4052]
  • RAT sibling addition: WebSocket via gorilla/websocket ^[sample bd6dead7/strings.txt:9126]
  • Fallback: DNS-over-HTTPS (Cloudflare, Google, Quad9) ^[sample 0b6c65cd/strings-unpacked.txt:10859]
  • Exfil: application/json POST with steal finished! confirmation; Telegram integration (found tg:// url) ^[sample 0b6c65cd/strings-unpacked.txt:10877]

ATT&CK Mapping

  • T1555.003 — Credentials from Web Browsers
  • T1113 — Screen Capture
  • T1115 — Clipboard Data
  • T1082 — System Information Discovery
  • T1543.003 — Create or Modify System Process (Task Scheduler)
  • T1071.001 — Application Layer Protocol: WebSocket (RAT sibling)
  • T1071 — Application Layer Protocol (QUIC/HTTP3)
  • T1572 — Protocol Tunneling (DoH)
  • T1567 — Exfiltration Over Web Service
  • T1083 — File and Directory Discovery
  • T1056.001 — Input Capture: Keylogging (RAT sibling)
  • T1059.003 — Windows Command Shell (RAT sibling)
  • T1090 — Proxy: SOCKS5 pivoting (RAT sibling)
  • T1134.001 — Access Token Manipulation (RAT sibling)
  • T1548.002 — Bypass User Access Control (RAT sibling)
  • T1564.011 — Hide Artifacts: Hidden Desktop (RAT sibling)
  • T1070.004 — Indicator Removal: File Deletion (RAT sibling)

Capabilities

  • credential-harvesting-chrome-dpapi
  • credential-harvesting-firefox-nss
  • credential-harvesting-brave-ielevator
  • crypto-wallet-seed-extraction
  • crypto-wallet-file-extraction
  • telegram-desktop-data-theft
  • steam-credential-theft
  • clipboard-hijack-cryptocurrency
  • system-information-enumeration
  • screen-capture-bitmap
  • quic-http3-c2-transport
  • websocket-c2-transport
  • socks5-proxy-pivoting
  • dns-over-https-fallback
  • wasm-in-process-module-loader
  • windows-task-scheduler-persistence
  • ton-blockchain-address-generation
  • sqlite3-browser-database-parsing
  • browser-cookie-sqlite-extraction
  • gecko-cookie-json-extraction
  • json-exfiltration-post
  • telegram-bot-exfiltration
  • machineguid-fingerprinting
  • keylogger-raw-input
  • remote-shell-execution
  • hidden-desktop-session
  • token-duplication-privilege-escalation
  • chrome-app-bound-encryption-bypass
  • process-suspension
  • file-download-upload
  • self-deletion

Related