NyashTeam
NyashTeam is a Russian-speaking malware-as-a-service (MaaS) operator active since approximately 2022. The group is associated with the NyashTeam / WebRat brand and is described as selling remote access trojans and stealer malware, including WebRAT (also referred to in reporting as SalatStealer) and DCRat (DarkCrystal RAT), via Telegram bots and websites. Reporting also describes NyashTeam as offering custom-made malware and server hosting to Russian-speaking cybercriminals. NyashTeam is linked to the operation and sale of SalatStealer/WebRAT, a Go-based malware family that combines RAT and infostealer functionality. Reported capabilities include theft of browser credentials and cookies, cryptocurrency wallet data, Telegram Desktop data, Discord tokens, Steam data, clipboard monitoring, keylogging, screen/webcam/microphone capture, remote shell access, SOCKS5 proxying, persistence, task scheduling, privilege escalation, and LSASS targeting. SalatStealer/WebRAT has been reported to use encrypted configuration, DNS-over-HTTPS and TON DNS-based C2 resolution, and WebSocket over TLS with QUIC/HTTP3 for exfiltration. The group’s operator portal was reported at nyash[.]team, advertising itself as the "OFFICIAL WebRat reseller." Sales and support were conducted through Telegram bots including @nyash_team_bot and @nyashsupbot. Infrastructure linked in reporting includes domains such as nyash[.]team, webrat[.]ru, webrat[.]top, wrat[.]in, salat[.]cn, and sa1at[.]ru, with Russian-hosted infrastructure in Moscow, Rostov-na-Donu, and Saint Petersburg also described. CERT-F6/F6 reportedly disrupted more than 110 NyashTeam domains in July 2025, but subsequent reporting states the group rebuilt infrastructure within months. Known aliases and associated branding directly mentioned in the content include WebRat and NyashTeam / WebRat.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Academia & Research
Where they target
Geographies tied to known operations.
- 🇺🇦 Ukraine
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-speaking malware-as-a-service group operating and distributing SalatStealer/WebRAT, selling access since approximately 2022, rebuilding infrastructure after prior disruption, and using TON blockchain DNS for resilient C2. The group also distributes DCRat and has used fake CVE PoC GitHub repositories and Telegram channels for delivery.
Operating a malware-as-a-service platform tied to SalatStealer, with reseller infrastructure, affiliate routing, Cloudflare-fronted exfiltration domains, Beget-hosted backends, and Telegram-based sales/support.
NyashTeam is a cybercriminal group selling WebRAT and DCRat, malware used for remote access, data theft, and spyware functions, often distributed via fake PoC exploits.
NyashTeam is a Russian-speaking cybercriminal group offering Salat Stealer (aka WEB_RAT or WebRAT) as malware-as-a-service, targeting browser credentials and cryptocurrency wallets.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.