Gremlin Stealer Abuses .NET Resource Files To Conceal Malware Payloads
ID: b581fc13-70aa-517d-908f-9101980f1407
STIX ID: report--b581fc13-70aa-517d-908f-9101980f1407
Feed Name: Cyber Press
Threat Score
Gremlin stealer is an evolved .NET infostealer that conceals payloads in resource sections and employs XOR decryption, staged in-memory loading, and heavy obfuscation to evade detection. It targets payment cards, browser cookies, session tokens, clipboard cryptocurrency wallets (via a crypto-clipper), Discord tokens, and VPN/FTP credentials, and the report provides several IOCs (an IP/URL and three SHA256 hashes) while noting low detection on scanning platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
