Gomorrah stealer

First seen
2020-03-01 00:00:00
Malware type
credential-stealer, loader
Family
Malware family
Profile updated
2026-07-07 15:03:40

Targeted industries: financial-services technology-and-telecommunications

Context

Gomorrah is a stealer with no or little obfuscation that appeared around March 2020. It is sold for about 150$ lifetime for v4 (originally 400$ for v3) or 100$ per month by its developer called "th3darkly / lucifer" (which is also the developer of CosaNostra botnet). The malware's main functionalities are stealing (passwords, cryptocurrency wallets) and loading of tasks and other payloads.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Gomorrah Stealer (report)
  • twitter.com — 1469713783308357633 (report)
  • github.com — April (report)

External references