Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
May 15, 2026, 7:14 p.m.
Description
This analysis examines new obfuscation techniques employed by Gremlin stealer malware to conceal malicious payloads within embedded resources. A variant protected by sophisticated commercial packing utility uses instruction virtualization, transforming code into custom bytecode executed by a private virtual machine. The malware siphons sensitive information including payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP/VPN credentials from compromised systems. It exfiltrates data to attacker-controlled servers at hxxp[:]194.87.92[.]109 for potential publication or sale. Recent iterations incorporate expanded Discord token extraction, active financial fraud through crypto clipper functionality that replaces cryptocurrency wallet addresses in real-time, and WebSocket-based session hijacking to bypass modern cookie protections. The malware employs advanced anti-analysis techniques including XOR-encoded payloads in .NET resource sections, identifier renaming, string encryp...
Tags
Date
- Created: May 15, 2026, 3:23 p.m.
- Published: May 15, 2026, 3:23 p.m.
- Modified: May 15, 2026, 7:14 p.m.
Indicators
- 971198ff86aeb42739ba9381923d0bc6f847a91553ec57ea6bae5becf80f8759
- f76ba1a4650d8cafb6d3ff071688c5db6fd37e165050f03cece693826f51d346
- 9aab30a3190301016c79f8a7f8edf45ec088ceecad39926cfcf3418145f3d614
- 2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b
- a9f529a5cbc1f3ee80f785b22e0c472953e6cb226952218aecc7ab07ca328abd
- ab0fa760bd037a95c4dee431e649e0db860f7cdad6428895b9a399b6991bf3cd
- 691896c7be87e47f3e9ae914d76caaf026aaad0a1034e9f396c2354245215dc3
- 281b970f281dbea3c0e8cfc68b2e9939b253e5d3de52265b454d8f0f578768a2
- d11938f14499de03d6a02b5e158782afd903460576e9227e0a15d960a2e9c02c
- 9fda1ddb1acf8dd3685ec31b0b07110855832e3bed28a0f3b81c57fe7fe3ac20
- 1bd0a200528c82c6488b4f48dd6dbc818d48782a2e25ccd22781c5718c3f62f5
- 194.87.92.109