typetechniqueconfidencehighcreated2026-08-15updated2026-08-15defense-evasionprocess-injectionwasmwebassemblyloader

WebAssembly In-Process Loader

Overview

Malware embedding a WebAssembly (Wasm) runtime to load and execute compiled .wasm modules inside the same process. This provides architecture-agnostic payload delivery and can evade signature-based detection that targets native code patterns.

Why It Matters

  • Wasm modules are position-independent and can be JIT-compiled at runtime.
  • Memory isolation via linear memory can frustrate memory-dumping tools that expect native PE layout.
  • Go's wazero library provides a pure-Go Wasm runtime with no external dependencies, making it attractive for Go-based malware.

Observed In

  • afk-stealer — Go-based infostealer using github.com/tetratelabs/wazero as an embedded Wasm runtime. Purpose inferred: plugin/module loading or payload decryption. ^[/intel/analyses/0b6c65cde50cae62eb3e15a9857193abd2ed130f8d73de6afc3e58ac2397c49a.html]

Detection

  • Look for wazero or wasmtime strings in memory.
  • Unusual .text section growth from JIT compilation of Wasm linear memory.
  • Suspicious API patterns: wazero.Runtime, wazero.ModuleConfig, wazero.FSConfig.

ATT&CK Mapping

  • T1620 — Reflective Code Loading
  • T1055 — Process Injection

Related