Gremlin Stealer Stores C2 URLs and Exfiltration Paths in Encrypted Resource Sections
ID: 53ed58a9-0a0b-5d1b-9f24-e74b0e1b53ff
STIX ID: report--53ed58a9-0a0b-5d1b-9f24-e74b0e1b53ff
Feed Name: cybersecurityNews.com
A newly observed Gremlin stealer variant conceals its command-and-control URLs and upload paths inside XOR-encrypted .NET resource sections and uses identifier renaming, string encryption, control-flow obfuscation, and staged loading to evade static analysis. The malware steals browser credentials, cookies, crypto wallet data (including real-time clipboard hijacking), Discord tokens, and other sensitive information, bundles exfiltrated data into ZIPs named after victims' public IPs, and uploads them to attacker-controlled infrastructure; the report includes a C2 IP and multiple SHA256 IoCs and recommends behavioral detection over signature-only approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
