GaboonGrabber

Malware type
dropper, credential-stealer, keylogger, trojan
Family
Malware family
Profile updated
2026-07-07 14:41:57

Context

According to ANY.RUN, the GaboonGrabber is a malware developed in .NET that grabs its embedded resources to prepare multiple fileless stages. Additionally, it has the tendency to camouflage itself as a legitimate application, going so far as to mimic legitimate applications in its decompiled code. It also includes a steganographic image used to prepare further payloads. GaboonGrabber's final stage can deploy various types of malware, including Snake Keylogger, AgentTesla, Redline, Lokibot, and more.

Reports & references

  • any.run — Reverse Engineering Snake Keylogger (report)
  • ciphertechsolutions.com — Roboski Global Recovery Automation (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Gaboongrabber (report)
  • app.any.run — 65855217 7209 4Eae A572 B030A2305B22 (report)

External references