logo

GoFlateLoader: The Bloated Golang Malware Smuggling Infostealers Past Scanners

ID: 0524bc8b-54b3-5470-89ed-251701229e4a

STIX ID: report--0524bc8b-54b3-5470-89ed-251701229e4a

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Do Son

...
...

Gen Threat Labs reports on GoFlateLoader, a Golang-based loader that evades detection by appending huge padded overlays (typically 700–950 MB) so scanners skip deep analysis and by loading infostealer payloads directly in memory; it drops stealers such as Amatera, Remus, Lumma, Vidar, StealC, and SvitStealer and is distributed via cracked software and malicious landing pages — defenders should treat oversized executables and cracked downloads with caution and can look for a distinctive hardcoded-call pattern during handoff.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.