logo

Gremlin Stealer Abuses .NET Resource Files To Conceal Malware Payloads

ID: b581fc13-70aa-517d-908f-9101980f1407

STIX ID: report--b581fc13-70aa-517d-908f-9101980f1407

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Varshini

...
...

Gremlin stealer is an evolved .NET infostealer that conceals payloads in resource sections and employs XOR decryption, staged in-memory loading, and heavy obfuscation to evade detection. It targets payment cards, browser cookies, session tokens, clipboard cryptocurrency wallets (via a crypto-clipper), Discord tokens, and VPN/FTP credentials, and the report provides several IOCs (an IP/URL and three SHA256 hashes) while noting low detection on scanning platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.