logo

Gremlin Stealer Uses Encrypted Resources to Store Exfiltration Paths

ID: 8e84fa6a-e1ae-5622-86d2-e527ef86ee8d

STIX ID: report--8e84fa6a-e1ae-5622-86d2-e527ef86ee8d

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Varshini

...
...

The report describes a new, highly obfuscated Gremlin stealer variant that uses commercial packing to convert code into custom bytecode and hides payloads in .NET resources with XOR encoding; it employs identifier renaming, string encryption, control-flow obfuscation and staged decryption, and includes modules for Discord token theft, a real-time cryptocurrency clipboard clipper, and WebSocket-based session hijacking. The authors publish exfiltrated data to an attacker-controlled site (http:194.87.92.109) and the report provides two SHA256 hashes as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.