Malware
Gremlin Stealer
- First Reported
- Jun 24, 2026
- Latest Reported
- Jun 24, 2026
Reported Context (1)
- the IP 194.87.92[.]109 was directly identified by Unit 42 as an exfiltration server for the evolved Gremlin Stealer variant. The stealer hides its payload and configuration in a .NET resource section using XOR Hunt.io Maps 3,923 Potentially Malicious Infrastructure Endpoints Across Eastern Europe
CVE (4)
Malware (12)
People (4)
Threat Actors (9)
MITRE ATT&CK (7)
Vendors (26)
Products (11)
Tools (9)
Industries (3)
Countries (10)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.