Researchers reported that GoFlateLoader, a Go-based malware loader, has infected more than 33,000 unique users since at least April 2026 by delivering multiple information stealers, including Lumma, Vidar, StealC, Amatera, Remus, and SvitStealer. The malware executes payloads entirely in memory by manually decoding and mapping a PE file without writing it to disk, reducing the chance of disk-based detection. Countries reported as most affected include Brazil, India, Argentina, Mexico, Turkey, and Spain.
The loader’s standout evasion method is extreme file-size inflation: samples commonly reach 700 MB to 950 MB because of a massive appended PE overlay, a tactic believed to help bypass upload and scanning limits in antivirus, EDR, sandbox, and threat-intelligence pipelines such as VirusTotal. Researchers said GoFlateLoader has been spread through fake cracked software and a malicious traffic distribution system that serves password-protected archives from landing pages, while also noting that use of Go’s syscall.Syscall with hardcoded dummy arguments may provide a useful detection marker.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-11, follow-on reporting highlighted researchers' observation that GoFlateLoader uses Go's syscall.Syscall with hardcoded dummy arguments, which may serve as a detection marker. The report reiterated the loader's use of oversized PE overlays and delivery of multiple infostealers.
On 2026-06-10, Gen Digital published research describing GoFlateLoader's use of a massive 700–950 MB PE overlay to evade scanning limits and its in-memory execution of PE payloads. The report identified heavily affected countries including Brazil, India, Argentina, Mexico, Turkey, and Spain.
Gen Digital said that since the beginning of April 2026 it had protected more than 33,000 unique users from GoFlateLoader worldwide. The loader was observed delivering multiple infostealers including Amatera, Remus, Lumma, Vidar, StealC, and SvitStealer.
Gen Digital reported that GoFlateLoader has been active since at least April 2026. The Go-based loader has been distributed via cracked software and a malicious traffic distribution system serving password-protected archives.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.