Gremlin Stealer Malware Targets Browsers, Crypto Wallets, and VPNs in Telegram-Based Campaign
ID: 32d23c69-3e82-548a-a61a-1519fda0f4c9
STIX ID: report--32d23c69-3e82-548a-a61a-1519fda0f4c9
Feed Name: securityonline.info
Unit 42 describes Gremlin Stealer, a newly observed, actively developed C# infostealer sold via a Telegram group that harvests browser data (including bypassing Chrome V20 cookie protections), crypto wallet files, session credentials and screenshots, then uploads collected data to a C2 server (207.244.199.46) and a Telegram bot; the report highlights its self-contained, modular design, active development, and recommends layered defenses including monitoring outbound connections and blocking known infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
