logo

Gremlin Stealer Hides Payloads in .NET Resources to Evade Detection

ID: 73b3d175-76a1-5806-9265-60e4128b1f4e

STIX ID: report--73b3d175-76a1-5806-9265-60e4128b1f4e

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

Author: Mayura Kathir

...
...

A newly observed Gremlin Stealer variant uses .NET resource embedding with XOR-encoded payloads, staged in-memory decryption, identifier/string/control-flow obfuscation, and commercial packers to evade static detection; it steals browser credentials, cookies, session tokens, crypto wallets, Discord tokens, and performs clipboard crypto clipping. Researchers identified an active exfiltration server at http://194.87.92.109 and a packed sample (SHA256 2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b), and recommend monitoring outbound traffic, memory-resident behavior, and deploying advanced endpoint detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.