WebAssembly In-Process Loader
Overview
Malware embedding a WebAssembly (Wasm) runtime to load and execute compiled .wasm modules inside the same process. This provides architecture-agnostic payload delivery and can evade signature-based detection that targets native code patterns.
Why It Matters
- Wasm modules are position-independent and can be JIT-compiled at runtime.
- Memory isolation via linear memory can frustrate memory-dumping tools that expect native PE layout.
- Go's
wazerolibrary provides a pure-Go Wasm runtime with no external dependencies, making it attractive for Go-based malware.
Observed In
- afk-stealer — Go-based infostealer using
github.com/tetratelabs/wazeroas an embedded Wasm runtime. Purpose inferred: plugin/module loading or payload decryption. ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html]
Detection
- Look for
wazeroorwasmtimestrings in memory. - Unusual
.textsection growth from JIT compilation of Wasm linear memory. - Suspicious API patterns:
wazero.Runtime,wazero.ModuleConfig,wazero.FSConfig.
ATT&CK Mapping
- T1620 — Reflective Code Loading
- T1055 — Process Injection
Related
- quic-http3-c2-transport — C2 transport used by same family