Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Top 10 Best MAST Tools for Mobile App Security Application Testing
May 28, 2026
Threat Actors Spoof FIFA Sites to Steal Personal Data
May 28, 2026
Top 10 SAST Tools for Security Teams in Best Static
May 28, 2026
Home/Threats/Gremlin Stealer Hides C2 URLs in Stores Exfiltration
Threats

Gremlin Stealer Hides C2 URLs in Stores Exfiltration

Security researchers have uncovered a new variant of the Gremlin stealer first appeared on underground forums, sold as a ready-to-use credential theft tool. It targets web browsers, clipboard...

Emy Elsamnoudy
Emy Elsamnoudy
May 21, 2026 3 Min Read
21 0

Security researchers have uncovered a new variant of the

Gremlin stealer first appeared on underground forums, sold as a ready-to-use credential theft tool. It targets web browsers, clipboard contents, and local storage to pull out payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP and VPN credentials.

Once it gathers this data, the malware bundles everything into a ZIP archive named after the victim’s public IP address and quietly uploads it to an attacker-controlled web panel for download or resale.

Analysts at Unit 42, the threat intelligence division of Palo Alto Networks, said in a report shared with Cyber Security News (CSN) that they identified a new Gremlin variant pushing stolen data to a freshly deployed server at hxxp[:]194.87.92[.]109.

At the time of discovery, no security vendor on VirusTotal had flagged the site as malicious, meaning the infrastructure was running completely under the radar.

What makes this variant particularly concerning is how quickly it has evolved. Legacy Gremlin samples had no obfuscation at all, with function names and class labels left exposed in plain sight.

The latest builds show a sharp turn toward stealth, layering multiple anti-analysis tricks to frustrate both automated tools and human researchers.

The malware has also broadened what it targets. Beyond browser credentials and crypto wallets, it now includes a dedicated module to steal Discord tokens, giving attackers access to the victim’s online accounts.

A clipboard hijacker has also been added, silently swapping any cryptocurrency wallet address a victim copies with one controlled by the attacker, diverting funds in real time.

Gremlin Stealer Stores C2 URLs and Exfiltration Paths

The most significant technical change is where the malware stores its core configuration. Rather than embedding C2 URLs as readable strings, the authors have moved that data into the .NET resource section, scrambled with XOR encoding.

Resource section (Source - Unit42)
Resource section (Source – Unit42)

The resource block appears as a meaningless wall of raw data to any static analysis tool. When researchers applied a single-byte XOR decryption routine, they recovered the plaintext configuration including hard-coded server addresses and upload paths.

XOR decryption on resource section (Source - Unit42)
XOR decryption on resource section (Source – Unit42)

This technique mirrors tactics used by malware families like Agent Tesla, GuLoader, LokiBot, and Quasar RAT, which rely on the resource section to bury their payloads.

The current variant also uses a staged loading approach, meaning each function is only decrypted and placed into memory when needed.

This forces analysts to use live debugging tools to observe the malware’s actual behavior, since nothing meaningful shows up in a static review.

Deep Code Obfuscation Blocks Reverse Engineering

Beyond hiding C2 data in resources, this variant uses three distinct obfuscation layers to slow down analysis.

The first is identifier renaming, where every class, method, and variable has been swapped with a meaningless short label like a, b, hf, or bb, removing any context that would help a researcher understand what a function does.

The second layer is string encryption. Rather than writing readable words like “password” or server addresses directly in the code, the malware stores all strings encrypted and decodes them at runtime using an internal function.

Packed Gremlin variant (Source - Unit42)
Packed Gremlin variant (Source – Unit42)

Analysts searching for keywords like “Telegram” or “wallet.dat” will find nothing. The third layer is control-flow obfuscation, which floods the decompiled output with fake branches, pointless loops, and goto jumps that lead nowhere meaningful.

Even though the actual logic is often a simple sequence of steps, the surrounding noise makes the code appear extraordinarily complex.

Organizations are strongly advised to rely on behavioral detection tools rather than signature-based scanning alone, as this malware is specifically engineered to defeat static analysis.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP / URL hxxp[:]194.87.92[.]109/i.php Gremlin stealer C2 exfiltration server
SHA256 2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b Packed Gremlin stealer sample (217.exe)
SHA256 9aab30a3190301016c79f8a7f8edf45ec088ceecad39926cfcf3418145f3d614 Gremlin stealer sample
SHA256 971198ff86aeb42739ba9381923d0bc6f847a91553ec57ea6bae5becf80f8759 Gremlin stealer sample
SHA256 ab0fa760bd037a95c4dee431e649e0db860f7cdad6428895b9a399b6991bf3cd Gremlin stealer sample
SHA256 f76ba1a4650d8cafb6d3ff071688c5db6fd37e165050f03cece693826f51d346 Gremlin stealer sample
SHA256 a9f529a5cbc1f3ee80f785b22e0c472953e6cb226952218aecc7ab07ca328abd Gremlin stealer sample
SHA256 691896c7be87e47f3e9ae914d76caaf026aaad0a1034e9f396c2354245215dc3 Gremlin stealer sample
SHA256 281b970f281dbea3c0e8cfc68b2e9939b253e5d3de52265b454d8f0f578768a2 Gremlin stealer sample
SHA256 9fda1ddb1acf8dd3685ec31b0b07110855832e3bed28a0f3b81c57fe7fe3ac20 Gremlin stealer sample
SHA256 d11938f14499de03d6a02b5e158782afd903460576e9227e0a15d960a2e9c02c Gremlin stealer sample
SHA256 1bd0a200528c82c6488b4f48dd6dbc818d48782a2e25ccd22781c5718c3f62f5 Gremlin steal

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Hackers Infect Windows with Fake Income Tax Assessment Pages

Next Post

Dark Web Brokers Resell Old Breaches as Repackage Fresh

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Notepad++ Flaws Allow Arbitrary Code Execution
May 28, 2026
Silent Ransom Group Attacks Law Firms via IT Support Imp
May 28, 2026
SBI Warns: Scammers Target YONO App Deactivation Sending Fake
May 28, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us