GoFlateLoader Uses Large PE Overlay to Deliver Multiple Infostealers
Key Takeaways A new malware loader, GoFlateLoader, written in Go, is actively distributing multiple information-stealing malware variants globally. The loader employs a simple yet effective evasion...
Key Takeaways
- A new malware loader, GoFlateLoader, written in Go, is actively distributing multiple information-stealing malware variants globally.
- The loader employs a simple yet effective evasion technique: artificially inflating its file size (700-950 MB) using a large PE overlay to bypass size-limited security scanning tools like VirusTotal.
- Since April 2026, over 33,000 unique users across countries like Brazil, India, and Mexico have been impacted by GoFlateLoader, which delivers infostealers such as Lumma, Vidar, and StealC.
- GoFlateLoader executes its payloads entirely in memory, further complicating detection by traditional file-based antivirus solutions.
GoFlateLoader: A New Threat Exploiting Simple Evasion
A novel malware loader named GoFlateLoader is rapidly expanding its presence across the digital landscape. Developed in the Go programming language, this loader distinguishes itself not through intricate technical sophistication, but by effectively utilizing a straightforward method: it employs an oversized PE overlay to deliver various dangerous information-stealing programs onto victim systems while evading detection.
Table Of Content
This loader’s primary function is to decode and deploy malicious payloads without triggering common security mechanisms. Its strategy for remaining undetected relies on making itself too large for many security analysis tools to process efficiently.
Since its emergence in April 2026, GoFlateLoader has already affected more than 33,000 distinct users worldwide. The campaign exhibits a broad reach, with significant impact observed in nations including Brazil, India, Argentina, Mexico, Turkey, and Spain, indicating an active and persistent threat.
The loader has been observed delivering a range of notorious infostealers, such as Lumma, Vidar, StealC, Amatera, Remus, and SvitStealer.
Under the Hood: How GoFlateLoader Operates
Researchers at Gen Digital have been actively monitoring GoFlateLoader, highlighting its unique characteristic: a deliberate lack of complex evasion techniques. As stated in a report shared with Cyber Security News (CSN), the loader foregoes typical anti-debugging, virtual machine detection, and sandbox-evasion logic commonly found in modern malware. Instead, it relies on one remarkably simple tactic to avoid scrutiny.
GoFlateLoader primarily infiltrates systems through two main channels: distributing fake cracked software and leveraging malicious traffic distribution systems, a method recently detailed by Check Point Research. In the latter scenario, users are redirected to a landing page presenting a password-protected archive. Crucially, the password for this archive is displayed separately, hindering automated security tools from unpacking and scanning its contents.
Upon execution, the loader decodes its malicious payload entirely within the computer’s memory, ensuring that the final infostealer never writes itself to the hard drive. This in-memory execution is a well-known technique used to bypass security software that monitors disk-based file activity. Researchers also note that the use of Go’s syscall.Syscall function as a transfer mechanism, coupled with hardcoded dummy arguments, presents an unusual behavioral signature that could serve as a valuable indicator for detection.
GoFlateLoader’s Massive PE Overlay Strategy
The defining characteristic of GoFlateLoader is its exceptionally large file size, typically ranging from 700 to 950 megabytes. This substantial size is a deliberate design choice.
The loader achieves this by appending a massive block of data, known as a PE overlay, to the end of its executable code. In most samples analyzed, this additional data consists of null bytes, though some variants employ random padding.
The primary objective of this file inflation is to circumvent the size limitations imposed by many security analysis tools, including antivirus engines, endpoint detection solutions, and cloud-based sandboxes. For instance, VirusTotal, a widely used threat intelligence platform, has an upload limit of 650 MB. GoFlateLoader’s consistent size, just above this threshold, strongly suggests it was specifically engineered to bypass such constraints. Despite its large size when uncompressed, the inflated data compresses significantly for distribution, enabling efficient and low-cost delivery for threat actors.
Payloads Delivered and the Threat They Pose
The ultimate payloads distributed by GoFlateLoader are exclusively information stealers, malicious programs designed to surreptitiously collect sensitive data such as saved passwords, browser history, and cryptocurrency wallet credentials from compromised systems.
Commonly observed payloads include Amatera, Remus, and Lumma, with Vidar, StealC, and SvitStealer also documented in active campaigns. The loader is available in both 32-bit and 64-bit versions, each tailored to match the architecture of the infostealer it is designed to deploy.
What You Should Do
- Exercise Caution with Downloads: Avoid downloading software from unofficial, untrusted, or suspicious sources, especially cracked versions or free alternatives to commercial programs.
- Maintain Up-to-Date Security Software: Ensure your antivirus and endpoint detection and response (EDR) solutions are regularly updated with the latest threat definitions.
- Implement Memory-Based Threat Detection: Prioritize security tools capable of detecting in-memory threats, as GoFlateLoader’s payloads do not write to disk, rendering traditional file-based scanning ineffective.
- Employ Strong Password Practices: Use unique, complex passwords for all accounts and enable multi-factor authentication (MFA) wherever possible to protect against credential theft.
- Backup Critical Data: Regularly back up important files to an offline or secure cloud storage solution to mitigate potential data loss from infostealer attacks.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | b88c5744975d2abb447aecc6c090fee9f8580413f4612eecdc6ed1973e8a1739 |
Password-protected archive containing GoFlateLoader x64 variant loading Remus (pwd: 1234) |
| SHA-256 | ed5ae7f36453c5a23e9868a5729d67e0549a11f6dea54f5f52d654a8f51d4902 |
Archive containing GoFlateLoader x64 variant loading Remus |
| SHA-256 | 841c9297cb8a2e0ff89433d13c05bfc760eb2e98e251cb8fa785d2ad7cbac05f |
Archive containing GoFlateLoader x86 variant loading Amatera |
| SHA-256 | ece7c48eb411b24f26762ede83badb4a644c41d5777129381ac2541804d64fc2 |
Archive containing GoFlateLoader x86 variant loading Lumma |
| SHA-256 | 421ce2d2f49c23bbe9f60ef3b9cd38d7eb912ce02e56a61837656210069bd9e2 |
Archive containing GoFlateLoader x64 variant loading Vidar |
| SHA-256 | 121c2dc793b3873f75a29ec02241f94136de19c049382a50a50d0d5b99507073 |
GoFlateLoader x64 variant loading StealC |
| SHA-256 | 2415db5081cec9bfd14ad6da1a66169fd96f13a49010c319a73d1ed6fafd4efa |
GoFlateLoader x64 variant loading Vidar |
| SHA-256 | d9917ade3b4c125a95b5d3e6343cde26145dfbf569bd7e2a843fd0c6fc8ddc28 |
GoFlateLoader x64 variant loading Remus |
| SHA-256 | 4cf6893756f441522b94b36f10e5de0e47aeed4743f95c51650746d1ecf97e3d |
GoFlateLoader x64 variant loading SvitStealer |
| SHA-256 | 8b89d6c9152d3aab97aadd515ecb69ca72654db2f25425759ba4b646853d737d |
GoFlateLoader x86 variant loading Lumma |
| SHA-256 | 90ce4ff9da23ac150da0a8e17930cab1e369aa349fdc1b65691b70369145664a |
GoFlateLoader x86 variant loading Amatera |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.