logo

Gremlin Stealer Stores C2 URLs and Exfiltration Paths in Encrypted Resource Sections

ID: 53ed58a9-0a0b-5d1b-9f24-e74b0e1b53ff

STIX ID: report--53ed58a9-0a0b-5d1b-9f24-e74b0e1b53ff

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Tushar Subhra Dutta

...
...

A newly observed Gremlin stealer variant conceals its command-and-control URLs and upload paths inside XOR-encrypted .NET resource sections and uses identifier renaming, string encryption, control-flow obfuscation, and staged loading to evade static analysis. The malware steals browser credentials, cookies, crypto wallet data (including real-time clipboard hijacking), Discord tokens, and other sensitive information, bundles exfiltrated data into ZIPs named after victims' public IPs, and uploads them to attacker-controlled infrastructure; the report includes a C2 IP and multiple SHA256 IoCs and recommends behavioral detection over signature-only approaches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.