GaboonGrabber
- Malware type
- dropper, credential-stealer, keylogger, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 14:41:57
Context
According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless stages. Additionally, it has the tendency to camouflage itself as a legitimate application, going so far as to mimic legitimate applications in its decompiled code. It also includes a steganographic image used to prepare further payloads. GaboonGrabber's final stage can deploy various types of malware, including Snake Keylogger, AgentTesla, Redline, Lokibot, and more.
Reports & references
- any.run — Reverse Engineering Snake Keylogger (report)
- ciphertechsolutions.com — Roboski Global Recovery Automation (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Gaboongrabber (report)
- app.any.run — 65855217 7209 4Eae A572 B030A2305B22 (report)