Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Home/Threats/GoFlateLoader Uses Large PE Overlay to Deliver Multiple Infostealers
Threats

GoFlateLoader Uses Large PE Overlay to Deliver Multiple Infostealers

Key Takeaways A new malware loader, GoFlateLoader, written in Go, is actively distributing multiple information-stealing malware variants globally. The loader employs a simple yet effective evasion...

Emy Elsamnoudy
Emy Elsamnoudy
June 11, 2026 4 Min Read
45 0

Key Takeaways

  • A new malware loader, GoFlateLoader, written in Go, is actively distributing multiple information-stealing malware variants globally.
  • The loader employs a simple yet effective evasion technique: artificially inflating its file size (700-950 MB) using a large PE overlay to bypass size-limited security scanning tools like VirusTotal.
  • Since April 2026, over 33,000 unique users across countries like Brazil, India, and Mexico have been impacted by GoFlateLoader, which delivers infostealers such as Lumma, Vidar, and StealC.
  • GoFlateLoader executes its payloads entirely in memory, further complicating detection by traditional file-based antivirus solutions.

GoFlateLoader: A New Threat Exploiting Simple Evasion

A novel malware loader named GoFlateLoader is rapidly expanding its presence across the digital landscape. Developed in the Go programming language, this loader distinguishes itself not through intricate technical sophistication, but by effectively utilizing a straightforward method: it employs an oversized PE overlay to deliver various dangerous information-stealing programs onto victim systems while evading detection.

Table Of Content

  • Key Takeaways
  • GoFlateLoader: A New Threat Exploiting Simple Evasion
  • Under the Hood: How GoFlateLoader Operates
  • GoFlateLoader’s Massive PE Overlay Strategy
  • Payloads Delivered and the Threat They Pose
  • What You Should Do
  • Indicators of Compromise (IoCs):-

This loader’s primary function is to decode and deploy malicious payloads without triggering common security mechanisms. Its strategy for remaining undetected relies on making itself too large for many security analysis tools to process efficiently.

Since its emergence in April 2026, GoFlateLoader has already affected more than 33,000 distinct users worldwide. The campaign exhibits a broad reach, with significant impact observed in nations including Brazil, India, Argentina, Mexico, Turkey, and Spain, indicating an active and persistent threat.

The loader has been observed delivering a range of notorious infostealers, such as Lumma, Vidar, StealC, Amatera, Remus, and SvitStealer.

Under the Hood: How GoFlateLoader Operates

Researchers at Gen Digital have been actively monitoring GoFlateLoader, highlighting its unique characteristic: a deliberate lack of complex evasion techniques. As stated in a report shared with Cyber Security News (CSN), the loader foregoes typical anti-debugging, virtual machine detection, and sandbox-evasion logic commonly found in modern malware. Instead, it relies on one remarkably simple tactic to avoid scrutiny.

GoFlateLoader primarily infiltrates systems through two main channels: distributing fake cracked software and leveraging malicious traffic distribution systems, a method recently detailed by Check Point Research. In the latter scenario, users are redirected to a landing page presenting a password-protected archive. Crucially, the password for this archive is displayed separately, hindering automated security tools from unpacking and scanning its contents.

Upon execution, the loader decodes its malicious payload entirely within the computer’s memory, ensuring that the final infostealer never writes itself to the hard drive. This in-memory execution is a well-known technique used to bypass security software that monitors disk-based file activity. Researchers also note that the use of Go’s syscall.Syscall function as a transfer mechanism, coupled with hardcoded dummy arguments, presents an unusual behavioral signature that could serve as a valuable indicator for detection.

GoFlateLoader’s Massive PE Overlay Strategy

The defining characteristic of GoFlateLoader is its exceptionally large file size, typically ranging from 700 to 950 megabytes. This substantial size is a deliberate design choice.

The loader achieves this by appending a massive block of data, known as a PE overlay, to the end of its executable code. In most samples analyzed, this additional data consists of null bytes, though some variants employ random padding.

The primary objective of this file inflation is to circumvent the size limitations imposed by many security analysis tools, including antivirus engines, endpoint detection solutions, and cloud-based sandboxes. For instance, VirusTotal, a widely used threat intelligence platform, has an upload limit of 650 MB. GoFlateLoader’s consistent size, just above this threshold, strongly suggests it was specifically engineered to bypass such constraints. Despite its large size when uncompressed, the inflated data compresses significantly for distribution, enabling efficient and low-cost delivery for threat actors.

Payloads Delivered and the Threat They Pose

The ultimate payloads distributed by GoFlateLoader are exclusively information stealers, malicious programs designed to surreptitiously collect sensitive data such as saved passwords, browser history, and cryptocurrency wallet credentials from compromised systems.

Commonly observed payloads include Amatera, Remus, and Lumma, with Vidar, StealC, and SvitStealer also documented in active campaigns. The loader is available in both 32-bit and 64-bit versions, each tailored to match the architecture of the infostealer it is designed to deploy.

What You Should Do

  • Exercise Caution with Downloads: Avoid downloading software from unofficial, untrusted, or suspicious sources, especially cracked versions or free alternatives to commercial programs.
  • Maintain Up-to-Date Security Software: Ensure your antivirus and endpoint detection and response (EDR) solutions are regularly updated with the latest threat definitions.
  • Implement Memory-Based Threat Detection: Prioritize security tools capable of detecting in-memory threats, as GoFlateLoader’s payloads do not write to disk, rendering traditional file-based scanning ineffective.
  • Employ Strong Password Practices: Use unique, complex passwords for all accounts and enable multi-factor authentication (MFA) wherever possible to protect against credential theft.
  • Backup Critical Data: Regularly back up important files to an offline or secure cloud storage solution to mitigate potential data loss from infostealer attacks.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 b88c5744975d2abb447aecc6c090fee9f8580413f4612eecdc6ed1973e8a1739 Password-protected archive containing GoFlateLoader x64 variant loading Remus (pwd: 1234)
SHA-256 ed5ae7f36453c5a23e9868a5729d67e0549a11f6dea54f5f52d654a8f51d4902 Archive containing GoFlateLoader x64 variant loading Remus
SHA-256 841c9297cb8a2e0ff89433d13c05bfc760eb2e98e251cb8fa785d2ad7cbac05f Archive containing GoFlateLoader x86 variant loading Amatera
SHA-256 ece7c48eb411b24f26762ede83badb4a644c41d5777129381ac2541804d64fc2 Archive containing GoFlateLoader x86 variant loading Lumma
SHA-256 421ce2d2f49c23bbe9f60ef3b9cd38d7eb912ce02e56a61837656210069bd9e2 Archive containing GoFlateLoader x64 variant loading Vidar
SHA-256 121c2dc793b3873f75a29ec02241f94136de19c049382a50a50d0d5b99507073 GoFlateLoader x64 variant loading StealC
SHA-256 2415db5081cec9bfd14ad6da1a66169fd96f13a49010c319a73d1ed6fafd4efa GoFlateLoader x64 variant loading Vidar
SHA-256 d9917ade3b4c125a95b5d3e6343cde26145dfbf569bd7e2a843fd0c6fc8ddc28 GoFlateLoader x64 variant loading Remus
SHA-256 4cf6893756f441522b94b36f10e5de0e47aeed4743f95c51650746d1ecf97e3d GoFlateLoader x64 variant loading SvitStealer
SHA-256 8b89d6c9152d3aab97aadd515ecb69ca72654db2f25425759ba4b646853d737d GoFlateLoader x86 variant loading Lumma
SHA-256 90ce4ff9da23ac150da0a8e17930cab1e369aa349fdc1b65691b70369145664a GoFlateLoader x86 variant loading Amatera

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

OceanLotus APT Uses FireAnt MetaKit Supply Chain Attack to Target Investors

Next Post

CISA Mandates Federal Agencies Patch Critical Ivanti EPMM Flaws in 3 Days

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Zapscape KVM Vulnerability CVE-2026-64561 Allows Guest-to-Host Escape
August 7, 2026
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us