Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

May 15, 2026, 7:14 p.m.

Description

This analysis examines new obfuscation techniques employed by Gremlin stealer malware to conceal malicious payloads within embedded resources. A variant protected by sophisticated commercial packing utility uses instruction virtualization, transforming code into custom bytecode executed by a private virtual machine. The malware siphons sensitive information including payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP/VPN credentials from compromised systems. It exfiltrates data to attacker-controlled servers at hxxp[:]194.87.92[.]109 for potential publication or sale. Recent iterations incorporate expanded Discord token extraction, active financial fraud through crypto clipper functionality that replaces cryptocurrency wallet addresses in real-time, and WebSocket-based session hijacking to bypass modern cookie protections. The malware employs advanced anti-analysis techniques including XOR-encoded payloads in .NET resource sections, identifier renaming, string encryp...

Indicators

  • 971198ff86aeb42739ba9381923d0bc6f847a91553ec57ea6bae5becf80f8759
  • f76ba1a4650d8cafb6d3ff071688c5db6fd37e165050f03cece693826f51d346
  • 9aab30a3190301016c79f8a7f8edf45ec088ceecad39926cfcf3418145f3d614
  • 2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b
  • a9f529a5cbc1f3ee80f785b22e0c472953e6cb226952218aecc7ab07ca328abd
  • ab0fa760bd037a95c4dee431e649e0db860f7cdad6428895b9a399b6991bf3cd
  • 691896c7be87e47f3e9ae914d76caaf026aaad0a1034e9f396c2354245215dc3
  • 281b970f281dbea3c0e8cfc68b2e9939b253e5d3de52265b454d8f0f578768a2
  • d11938f14499de03d6a02b5e158782afd903460576e9227e0a15d960a2e9c02c
  • 9fda1ddb1acf8dd3685ec31b0b07110855832e3bed28a0f3b81c57fe7fe3ac20
  • 1bd0a200528c82c6488b4f48dd6dbc818d48782a2e25ccd22781c5718c3f62f5
  • 194.87.92.109

Attack Patterns

  • GuLoader - S0561
  • Lokibot - S0447
  • Quasar RAT
  • Gremlin stealer
  • Agent Tesla - S0331