AFK Stealer
Overview
AFK Stealer (also AFKSystems) is a commodity Go-based information stealer sold on Russian-speaking cybercrime forums. Four confirmed siblings: 0b6c65cd, 6d8ecdd1, b07d5dcd, and bd6dead7 (this analysis). It targets browser credentials, cryptocurrency wallets, system information, and clipboard data. Version string [AFK] 0.28.1 (x86) is present in plaintext in observed samples. The fourth sibling (bd6dead7) adds a full RAT surface: WebSocket C2, SOCKS5 proxy pivoting, screen streaming, keylogging, remote shell, webcam/mic capture, hidden desktop, and token-duplication privilege escalation. ^[sample 0b6c65cd/strings-unpacked.txt:10854] ^[sample bd6dead7/strings.txt:10854]
Build Pattern
- Compiler: Go 1.24.0,
GOOS=windows,GOARCH=386(x86) ^[sample 0b6c65cd/file.txt] ^[sample bd6dead7/strings.txt:15425] - Packing: UPX 3.96 in siblings
0b6c65cd,6d8ecdd1,b07d5dcd; not UPX-packed in siblingbd6dead7(12.5 MB raw). ^[sample bd6dead7/triage.json] - Signing: Unsigned.
- Obfuscation: Stripped but retains Go
.symtabfunction names (no randomized names observed in this build). No debug checks or VM detection. - Resources: No
.rsrc, no version info, no icon. GUI subsystem with no visible window code.
Dependencies (Go Modules)
The sample embeds an unusually rich dependency graph for a stealer:
| Module | Purpose |
|---|---|
github.com/quic-go/quic-go |
QUIC/HTTP3 C2 transport with TLS 1.3 and 0-RTT |
github.com/gorilla/websocket |
WebSocket C2 transport (RAT sibling bd6dead7 only) ^[sample bd6dead7/strings.txt:9126] |
github.com/tetratelabs/wazero |
WebAssembly runtime for in-process plugin/module loading |
github.com/capnspacehook/taskmaster |
Windows Task Scheduler OLE automation for persistence |
github.com/ncruces/go-sqlite3 |
SQLite driver for browser credential database parsing |
github.com/xssnick/tonutils-go |
TON blockchain address/wallet operations |
golang.org/x/crypto |
ML-KEM768, X25519, ChaCha20-Poly1305 |
^[sample 0b6c65cd/strings-unpacked.txt:4052]
Targets
Browsers (15+)
Chrome, Edge, Brave, Opera, Opera GX, Firefox, Thunderbird, Yandex, SeaMonkey, Comodo Dragon, CocCoc, 360Browser, UR Browser, CentBrowser, Epic Privacy Browser, and others. ^[sample 0b6c65cd/strings-unpacked.txt:10854]
Crypto Wallets (40+)
Exodus, Armory, Guarda, MetaMask, TonKeeper, SuiWallet, AtomicWallet, Trust Wallet, Jaxx Liberty, TerraStation, Electrum, MyMonero, Coinbase, XMR.PT, Phantom, SafePal, Solfare, Enkrypt, and many more. ^[sample 0b6c65cd/strings-unpacked.txt:10854]
Other Targets
- Telegram Desktop (
tdatabpaths) - Steam (
local.vdf) - System clipboard (clipboard hijacking)
- MachineGuid
C2 / Exfiltration
- Primary: QUIC/HTTP3 via
quic-go(TLS 1.3, X25519+MLKEM768, 0-RTT) ^[sample 0b6c65cd/strings-unpacked.txt:4052] - RAT sibling addition: WebSocket via
gorilla/websocket^[sample bd6dead7/strings.txt:9126] - Fallback: DNS-over-HTTPS (Cloudflare, Google, Quad9) ^[sample 0b6c65cd/strings-unpacked.txt:10859]
- Exfil:
application/jsonPOST withsteal finished!confirmation; Telegram integration (found tg:// url) ^[sample 0b6c65cd/strings-unpacked.txt:10877]
ATT&CK Mapping
- T1555.003 — Credentials from Web Browsers
- T1113 — Screen Capture
- T1115 — Clipboard Data
- T1082 — System Information Discovery
- T1543.003 — Create or Modify System Process (Task Scheduler)
- T1071.001 — Application Layer Protocol: WebSocket (RAT sibling)
- T1071 — Application Layer Protocol (QUIC/HTTP3)
- T1572 — Protocol Tunneling (DoH)
- T1567 — Exfiltration Over Web Service
- T1083 — File and Directory Discovery
- T1056.001 — Input Capture: Keylogging (RAT sibling)
- T1059.003 — Windows Command Shell (RAT sibling)
- T1090 — Proxy: SOCKS5 pivoting (RAT sibling)
- T1134.001 — Access Token Manipulation (RAT sibling)
- T1548.002 — Bypass User Access Control (RAT sibling)
- T1564.011 — Hide Artifacts: Hidden Desktop (RAT sibling)
- T1070.004 — Indicator Removal: File Deletion (RAT sibling)
Capabilities
- credential-harvesting-chrome-dpapi
- credential-harvesting-firefox-nss
- credential-harvesting-brave-ielevator
- crypto-wallet-seed-extraction
- crypto-wallet-file-extraction
- telegram-desktop-data-theft
- steam-credential-theft
- clipboard-hijack-cryptocurrency
- system-information-enumeration
- screen-capture-bitmap
- quic-http3-c2-transport
- websocket-c2-transport
- socks5-proxy-pivoting
- dns-over-https-fallback
- wasm-in-process-module-loader
- windows-task-scheduler-persistence
- ton-blockchain-address-generation
- sqlite3-browser-database-parsing
- browser-cookie-sqlite-extraction
- gecko-cookie-json-extraction
- json-exfiltration-post
- telegram-bot-exfiltration
- machineguid-fingerprinting
- keylogger-raw-input
- remote-shell-execution
- hidden-desktop-session
- token-duplication-privilege-escalation
- chrome-app-bound-encryption-bypass
- process-suspension
- file-download-upload
- self-deletion
Related
- 54e64e — OpenCTI umbrella label (ninth morph under this label, but not build-related)
- browser-credential-harvesting — cross-family technique page
- golang-stealer-build-pattern — Go-based stealer build artefacts
- quic-http3-c2-transport — QUIC/HTTP3 C2 technique
- websocket-c2-transport — WebSocket C2 technique (RAT sibling)
- socks5-proxy-pivoting — SOCKS5 proxy pivoting technique (RAT sibling)
- wasm-in-process-loader — WebAssembly runtime embedding technique
- task-scheduler-persistence — Windows Task Scheduler persistence technique
- dns-over-https-fallback — DoH fallback technique
- token-duplication-privilege-escalation — Token duplication / privilege escalation technique (RAT sibling)
- app-bound-encryption-bypass — Chrome App-Bound Encryption bypass technique (RAT sibling)
- rat — concept page for remote-access tool capabilities