Gremlin Stealer: New Stealer on Sale in Underground Forum


Unit 42 researchers have identified new information-stealing malware written in C#, called Gremlin Stealer. This stealer’s authors have actively advertised it on a Telegram group since mid-March 2025.

This information-stealing malware exfiltrates data from its victims and uploads this information to its web server for publication. It can capture data from browsers, the clipboard and the local disk to steal sensitive data such as credit card details, browser cookies, crypto wallet information, File Transfer Protocol (FTP) and virtual private network (VPN) credentials. Gremlin Stealer’s authors predominantly distribute it through a Telegram channel named CoderSharp, and the malware is undergoing active development.

Read more…
Source: Trend Micro Unit 42


Sign up for our Newsletter
The latest news and insights delivered right to your inbox.


Related:

  • Italy’s top bank hit by an AI messaging scam which cost it nearly €100 million

    September 29, 2026

    Cybercriminals have tricked a major Italian bank into wiring more than $100 million abroad by targeting executives with AI-powered deepfakes. Some of the money has since been recovered, but a significant portion remains unaccounted for. The target was Fideuram – Intesa Sanpaolo Private Banking, a very large Italian private-banking and wealth-management group owned by Intesa Sanpaolo. ...

  • Fake iPhone Duo preorder scam triggers DarkSword attack

    September 29, 2026

    Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what MalwareBytes researchers found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different. Read more… Source:  MalwareBytes Labs Sign up for the Cyber Security Review ...

  • A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies

    September 28, 2026

    A former US Army soldier has been sentenced to 70 months in prison for hacking telecoms companies, stealing sensitive records, and trying to extort more than $1 million from his victims. Cameron John Wagenius, 22, carried out the campaign while serving on active duty. He pleaded guilty in March 2025 to unlawfully transferring confidential phone records, ...

  • Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

    September 25, 2026

    Technology giant Kiteworks is urging customers to shut down their systems after the company received information that hackers may attempt to target them. Kiteworks (formerly Accellion), which makes tools for transferring large files and sensitive datasets over the internet, confirmed to TechCrunch that it had notified its customers about a potential threat. The news was first ...

  • Australia: Rogue AI agents worked together for months to gain access to government health data

    September 24, 2026

    A swarm of OpenAI rogue AI agents appear to have gone on a spree of trying to access Australian government health data, in what some researchers say is the first autonomous hack of a government website. Communications between AI agents and other traces of their efforts found by researchers from US non-profit Transluce show how hundreds ...

  • CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM

    September 23, 2026

    On September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending ...