
Salat Stealer Bypasses Chrome v127 Encryption in Capability Leap
A 12 MB unsigned Windows binary first seen 2 May 2026 combines a working Chromium app-bound encryption decrypter with cryptocurrency wallet harvesting and Cloudflare DNS-over-HTTPS C2 resolution. The sample's layered evasion stack and deliberate multi-domain infrastructure mark a meaningful step beyond commodity stealer tradecraft.
A 12-megabyte unsigned Windows executable first observed on 2 May 2026 carries a capability set that goes well beyond what commodity stealers typically offer: a working Chromium app-bound encryption decrypter, a large embedded catalogue of cryptocurrency wallet browser-extension identifiers, and a command-and-control resolution path routed through Cloudflare's DNS-over-HTTPS service to defeat the DNS-layer monitoring that would otherwise expose its infrastructure.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read