logo

Bypassing MFA: Gremlin Stealer Evolves into Advanced Memory-Resident Session Hijacker

ID: 72c16f03-f06e-5af9-9c91-38e0154d7c05

STIX ID: report--72c16f03-f06e-5af9-9c91-38e0154d7c05

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

Gremlin stealer has evolved into a sophisticated, memory-resident infostealer that targets Chromium-based browsers to extract active session tokens, hijack communication platform tokens (notably Discord), and monitor/replace clipboard cryptocurrency addresses. Its modular design and use of control-flow flattening enable MFA bypass, account takeover, and robust anti-analysis evasion, increasing the risk of corporate, cloud, and financial account compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.