Gremlin Stealer Hides C2 and Exfiltration Paths in Encrypted Resources
ID: 89d7c9a7-e38f-56e7-98dd-ea1dfca650b1
STIX ID: report--89d7c9a7-e38f-56e7-98dd-ea1dfca650b1
Feed Name: GBHackers
A new Gremlin stealer variant uses .NET resource XOR-encoding, staged in-memory decryption, commercial packing (instruction virtualization), and multiple anti-analysis techniques to harvest browser-stored credentials, session tokens, cryptocurrency wallets, clipboard data (crypto clippers), Discord tokens, and VPN/FTP credentials; stolen data is compressed and exfiltrated to attacker-controlled infrastructure (IOC: http:194.87.92.109/i.php, multiple SHA256s) and is distributed via underground Telegram channels, with Unit 42 providing detection and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
