GoFlateLoader: The Bloated Golang Malware Smuggling Infostealers Past Scanners
ID: 0524bc8b-54b3-5470-89ed-251701229e4a
STIX ID: report--0524bc8b-54b3-5470-89ed-251701229e4a
Feed Name: securityonline.info
Gen Threat Labs reports on GoFlateLoader, a Golang-based loader that evades detection by appending huge padded overlays (typically 700–950 MB) so scanners skip deep analysis and by loading infostealer payloads directly in memory; it drops stealers such as Amatera, Remus, Lumma, Vidar, StealC, and SvitStealer and is distributed via cracked software and malicious landing pages — defenders should treat oversized executables and cracked downloads with caution and can look for a distinctive hardcoded-call pattern during handoff.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
