Summary: Gremlin Stealer is a newly identified infostealer that targets data from various software on Windows systems. Released in March 2025, it collects a wide range of sensitive information and exfiltrates it via a Telegram bot to a dedicated server. The malware employs advanced techniques to bypass security features and stores stolen data in easily accessible formats.
Affected: Organizations using Windows systems
Keypoints :
- Gremlin Stealer collects clipboard data, screenshots, metadata, and credential information from various browsers.
- It can bypass Chrome cookie protections and does not require internet downloads for its build process.
- Stolen data is archived and sent to a server at 207.244.199[.]46, with victims’ information stored in plain text files.
Source: https://www.infosecurity-magazine.com/news/new-gremlin-infostealer/