APTMembers
APT

Salat Stealer Bypasses Chrome v127 Encryption in Capability Leap

A 12 MB unsigned Windows binary first seen 2 May 2026 combines a working Chromium app-bound encryption decrypter with cryptocurrency wallet harvesting and Cloudflare DNS-over-HTTPS C2 resolution. The sample's layered evasion stack and deliberate multi-domain infrastructure mark a meaningful step beyond commodity stealer tradecraft.

Jun 17, 2026, 20:00 (UTC+9)Last seenJun 17, 2026Severity77ByCTX TeamActorAPT28StrontiumIOC8MITRE11

A 12-megabyte unsigned Windows executable first observed on 2 May 2026 carries a capability set that goes well beyond what commodity stealers typically offer: a working Chromium app-bound encryption decrypter, a large embedded catalogue of cryptocurrency wallet browser-extension identifiers, and a command-and-control resolution path routed through Cloudflare's DNS-over-HTTPS service to defeat the DNS-layer monitoring that would otherwise expose its infrastructure.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence