ThreatCluster

New Gremlin Stealer Variant Uses Encrypted Resources for Stealthy Data Theft

First seen 20 May 2026, 19:05 UTC GbhackersCybersecuritynews 85% similarity 59

Article Content

Browse articles
ThreatCluster

A new variant of the Gremlin stealer malware has emerged, utilizing advanced obfuscation techniques to hide its command-and-control infrastructure and data exfiltration methods within encrypted .NET resource sections. This malware targets sensitive information such as browser-stored credentials, session tokens, and cryptocurrency wallets. The Gremlin stealer is actively sold on Telegram, indicating a growing market for such infostealer tools. Security researchers have noted a significant reduction in detection rates due to these stealth-focused techniques. The malware's modularity and anti-analysis capabilities represent a concerning evolution in infostealer campaigns. As of now, there are no specific CVEs associated with this variant, but its impact on affected systems is expected to be substantial.

Key Points: • A new Gremlin stealer variant employs encrypted .NET resources to evade detection. • Targets include sensitive data like payment card details and cryptocurrency wallets. • The malware is actively sold on Telegram, indicating a thriving cybercriminal market.

ThreatCluster AI

Timeline

2026-05-18
Gremlin Stealer variant discovered
A new variant of the Gremlin Stealer was identified, using stealth techniques to reduce detection rates.
Gbhackers
2026-05-20
Advanced obfuscation techniques reported
The variant is found to conceal its C2 infrastructure and exfiltration logic within encrypted resources.
Gbhackers

Community

Browse all →

Tracked Entities in This Story