Malware & Tooling · Credential Theft

Gremlin Stealer Hides Payloads Beyond Static Detection

Gremlin Stealer has moved past simple packed binaries. Its latest builds hide malicious payloads in embedded resources and execute transformed bytecode inside a private virtual machine, which means static signatures and basic unpacking can miss the real code path.

Unit 42 says the variant also adds new anti-analysis safeguards and still targets browsers, clipboard, local storage, payment card data, session tokens, cryptocurrency wallets, and FTP and VPN credentials. It exfiltrates stolen data to attacker-controlled infrastructure for possible sale or publication.

The practical shift is in where defenders have to look. Runtime behavior, memory, and embedded resources now matter more than a file scan alone when hunting this stealer family.

2 sources · May 15

Timeline

Sources

Part of the PlainSec briefing for 2026-05-15

Every edition of this story: Gremlin Stealer Hides Payloads Beyond Static Detection

More from today