Gremlin Stealer: New Stealer on Sale in Underground Forum
ID: ffd91c65-d5af-5322-b440-f741ac8bb81d
STIX ID: report--ffd91c65-d5af-5322-b440-f741ac8bb81d
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-04-29
Date Updated: 2026-04-28
Author: Pranay Kumar Chhaparwal and Benjamin Chang
Unit 42 describes Gremlin Stealer, a C# information-stealer (similar to Sharp/Hannibal variants) advertised on Telegram and active since March 2025; it exfiltrates browser cookies/passwords, crypto wallets, clipboard, FTP/VPN credentials and messaging sessions to a backend server (207.244.199.46) and includes a SHA256 sample, code-level analysis of capabilities (including Chrome cookie v20 bypass), and recommended detections and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
