Gremlin Stealer has moved past simple packed binaries. Its latest builds hide malicious payloads in embedded resources and execute transformed bytecode inside a private virtual machine, which means static signatures and basic unpacking can miss the real code path.
Unit 42 says the variant also adds new anti-analysis safeguards and still targets browsers, clipboard, local storage, payment card data, session tokens, cryptocurrency wallets, and FTP and VPN credentials. It exfiltrates stolen data to attacker-controlled infrastructure for possible sale or publication.
The practical shift is in where defenders have to look. Runtime behavior, memory, and embedded resources now matter more than a file scan alone when hunting this stealer family.