Gomorrah stealer
- First seen
- 2020-03-01 00:00:00
- Malware type
- credential-stealer, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 15:03:40
Targeted industries: financial-services technology-and-telecommunications
Context
Gomorrah is a stealer with no or little obfuscation that appeared around March 2020. It is sold for about 150$ lifetime for v4 (originally 400$ for v3) or 100$ per month by its developer called "th3darkly / lucifer" (which is also the developer of CosaNostra botnet). The malware's main functionalities are stealing (passwords, cryptocurrency wallets) and loading of tasks and other payloads.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Gomorrah Stealer (report)
- twitter.com — 1469713783308357633 (report)
- github.com — April (report)