Malware · 139 days ago
Gremlin Stealer has moved past simple packed binaries. Its latest builds hide malicious payloads in embedded resources and execute transformed bytecode inside a private virtual machine, which means static signatures and basic unpacking can miss the real code path.
Unit 42 says the variant also adds new anti-analysis safeguards and still targets browsers, clipboard, local storage, payment card data, session tokens, cryptocurrency wallets, and FTP and VPN credentials. It exfiltrates stolen data to attacker-controlled infrastructure for possible sale or publication.
The practical shift is in where defenders have to look. Runtime behavior, memory, and embedded resources now matter more than a file scan alone when hunting this stealer family.
2 sources covering this story
Gremlin Stealer Evolves into Modular Threat
A new Gremlin stealer variant has evolved into a modular toolkit with advanced evasion and data theft capabilities, according to new Unit 42 research
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
Unit 42 analyzes the evolution of Gremlin stealer.
Part of the PlainSec briefing for 2026-05-16