PULSE NAME
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
WHITE AlienVault 2026-05-15 Modified: 2026-05-15
12
IOCs
MEDIUM VOLUME
This analysis examines new obfuscation techniques employed by Gremlin stealer malware to conceal malicious payloads within embedded resources. A variant protected by sophisticated commercial packing utility uses instruction virtualization, transforming code into custom bytecode executed by a private virtual machine. The malware siphons sensitive information including payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP/VPN credentials from compromised systems. It exfiltrates data to attacker-controlled servers at hxxp[:]194.87.92[.]109 for potential publication or sale. Recent iterations incorporate expanded Discord token extraction, active financial fraud through crypto clipper functionality that replaces cryptocurrency wallet addresses in real-time, and WebSocket-based session hijacking to bypass modern cookie protections. The malware employs advanced anti-analysis techniques including XOR-encoded payloads in .NET resource sections, identifier renaming, string encryp...
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Gremlin stealer Agent Tesla - S0331 GuLoader - S0561 Lokibot - S0447 Quasar RAT
Indicators of Compromise (12)
All IPv4 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
IPv4 194.87.92.109 2026-05-15
FileHash-SHA256 1bd0a200528c82c6488b4f48dd6dbc818d48782a2e25ccd22781c5718c3f62f5 2026-05-15
FileHash-SHA256 2172dae9a5a695e00e0e4609e7db0207d8566d225f7e815fada246ae995c0f9b 2026-05-15
FileHash-SHA256 281b970f281dbea3c0e8cfc68b2e9939b253e5d3de52265b454d8f0f578768a2 2026-05-15
FileHash-SHA256 691896c7be87e47f3e9ae914d76caaf026aaad0a1034e9f396c2354245215dc3 2026-05-15
FileHash-SHA256 971198ff86aeb42739ba9381923d0bc6f847a91553ec57ea6bae5becf80f8759 2026-05-15
FileHash-SHA256 9aab30a3190301016c79f8a7f8edf45ec088ceecad39926cfcf3418145f3d614 2026-05-15
FileHash-SHA256 9fda1ddb1acf8dd3685ec31b0b07110855832e3bed28a0f3b81c57fe7fe3ac20 2026-05-15
FileHash-SHA256 a9f529a5cbc1f3ee80f785b22e0c472953e6cb226952218aecc7ab07ca328abd 2026-05-15
FileHash-SHA256 ab0fa760bd037a95c4dee431e649e0db860f7cdad6428895b9a399b6991bf3cd 2026-05-15
FileHash-SHA256 d11938f14499de03d6a02b5e158782afd903460576e9227e0a15d960a2e9c02c 2026-05-15
FileHash-SHA256 f76ba1a4650d8cafb6d3ff071688c5db6fd37e165050f03cece693826f51d346 2026-05-15