logo

Gremlin Stealer Malware Targets Browsers, Crypto Wallets, and VPNs in Telegram-Based Campaign

ID: 32d23c69-3e82-548a-a61a-1519fda0f4c9

STIX ID: report--32d23c69-3e82-548a-a61a-1519fda0f4c9

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2025-05-01

Date Updated: 2026-04-22

Author: Ddos

...
...

Unit 42 describes Gremlin Stealer, a newly observed, actively developed C# infostealer sold via a Telegram group that harvests browser data (including bypassing Chrome V20 cookie protections), crypto wallet files, session credentials and screenshots, then uploads collected data to a C2 server (207.244.199.46) and a Telegram bot; the report highlights its self-contained, modular design, active development, and recommends layered defenses including monitoring outbound connections and blocking known infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.