Gremlin Stealer Evolves: New Variant Hides C2 URLs in Encrypted Resources and Adds Discord Token Theft
A newly analyzed Gremlin stealer variant hides C2 URLs inside XOR-encrypted .NET resource sections, making it invisible to static scanners. The malware now targets Discord tokens and adds a clipboard hijacker for real-time cryptocurrency theft, with new C2 infrastructure that evaded all VirusTotal detections at time of discovery.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.