logo

GoFlateLoader Hides Infostealers in Massive PE Overlay

ID: 89791be6-b204-5a5a-86aa-c1d81cc4b1d3

STIX ID: report--89791be6-b204-5a5a-86aa-c1d81cc4b1d3

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-06-11

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

GoFlateLoader is a Golang-based loader widely used to deliver multiple infostealers; it evades analysis by appending extremely large PE overlays (commonly 700–950 MB) and distributing via password-protected archives and cracked-software TDS landing pages. The loader performs an in-memory manual PE mapping of an encoded payload from .rdata, uses syscall.Syscall with dummy args as a call gate, and includes decoy code to hinder static analysis. Gen Threat Labs links it to several prevalent stealers (Lumma, Vidar, StealC, Amatera, Remus), provides multiple file-hash IoCs (many exceeding VirusTotal upload limits), and recommends blocking cracked software/TDS, handling large compressed artifacts, and policy for extracting page-provided archive passwords for analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.