logo

Gremlin Stealer Hides C2 and Exfiltration Paths in Encrypted Resources

ID: 89d7c9a7-e38f-56e7-98dd-ea1dfca650b1

STIX ID: report--89d7c9a7-e38f-56e7-98dd-ea1dfca650b1

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Mayura Kathir

...
...

A new Gremlin stealer variant uses .NET resource XOR-encoding, staged in-memory decryption, commercial packing (instruction virtualization), and multiple anti-analysis techniques to harvest browser-stored credentials, session tokens, cryptocurrency wallets, clipboard data (crypto clippers), Discord tokens, and VPN/FTP credentials; stolen data is compressed and exfiltrated to attacker-controlled infrastructure (IOC: http:194.87.92.109/i.php, multiple SHA256s) and is distributed via underground Telegram channels, with Unit 42 providing detection and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.