logo

Gremlin Stealer: New Stealer on Sale in Underground Forum

ID: ffd91c65-d5af-5322-b440-f741ac8bb81d

STIX ID: report--ffd91c65-d5af-5322-b440-f741ac8bb81d

Feed Name: Palo Alto Networks Unit 42

Threat Score
72/100

Date Published: 2025-04-29

Date Updated: 2026-04-28

Author: Pranay Kumar Chhaparwal and Benjamin Chang

...
...

Unit 42 describes Gremlin Stealer, a C# information-stealer (similar to Sharp/Hannibal variants) advertised on Telegram and active since March 2025; it exfiltrates browser cookies/passwords, crypto wallets, clipboard, FTP/VPN credentials and messaging sessions to a backend server (207.244.199.46) and includes a SHA256 sample, code-level analysis of capabilities (including Chrome cookie v20 bypass), and recommended detections and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.