Palo Alto Networks Unit 42 reported a new Gremlin Stealer variant that significantly increases stealth and anti-analysis protections while expanding data theft capabilities. The malware hides XOR-encoded payloads in the .NET resource section and, in at least one sample, uses a commercial packer with instruction virtualization to complicate reverse engineering. Researchers said recent builds also rely on staged loading, string encryption, identifier renaming, and control-flow obfuscation, while associated infrastructure had zero detections on VirusTotal when discovered.
The updated stealer targets browser cookies, session tokens, clipboard contents, cryptocurrency wallet data, and FTP/VPN credentials, then compresses stolen information into a ZIP archive named after the victim’s public IP address before uploading it to an attacker-controlled server at hxxp[:]194.87.92[.]109/i.php. Unit 42 said the latest variant also adds Discord token theft, clipboard-based cryptocurrency address replacement, and WebSocket-based browser session hijacking designed to bypass modern cookie protections, indicating a shift toward more covert credential theft and account takeover operations.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
The analysis identified attacker-controlled infrastructure at 194.87.92.109/i.php used to receive ZIP archives of stolen data named after victims’ public IP addresses. Unit 42 reported that this newly identified infrastructure had zero detections on VirusTotal at the time of discovery.
Unit 42 analyzed a new Gremlin Stealer variant that uses stronger obfuscation and anti-analysis techniques, including XOR-encoded payloads stored in the .NET resource section and, in one sample, a commercial packer with instruction virtualization. The variant also adds Discord token theft, clipboard-based cryptocurrency address replacement, and WebSocket-based browser session hijacking.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 12 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.