GoFlateLoader Hides Infostealers in Massive PE Overlay
ID: 89791be6-b204-5a5a-86aa-c1d81cc4b1d3
STIX ID: report--89791be6-b204-5a5a-86aa-c1d81cc4b1d3
Feed Name: GBHackers
GoFlateLoader is a Golang-based loader widely used to deliver multiple infostealers; it evades analysis by appending extremely large PE overlays (commonly 700–950 MB) and distributing via password-protected archives and cracked-software TDS landing pages. The loader performs an in-memory manual PE mapping of an encoded payload from .rdata, uses syscall.Syscall with dummy args as a call gate, and includes decoy code to hinder static analysis. Gen Threat Labs links it to several prevalent stealers (Lumma, Vidar, StealC, Amatera, Remus), provides multiple file-hash IoCs (many exceeding VirusTotal upload limits), and recommends blocking cracked software/TDS, handling large compressed artifacts, and policy for extracting page-provided archive passwords for analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
