#GoFlateLoader
GoFlateLoader:スキャナーをすり抜ける情報窃盗犯を密輸する、肥大化したGolangマルウェア

GoFlateLoader: The Bloated Golang Malware Smuggling Infostealers Past Scanners #DailyCyberSecurity (Jun 17)

securityonline.info/goflateloade...
GoFlateLoader: The Bloated Golang Malware Smuggling Infostealers Past Scanners
GoFlateLoader malware, a Golang loader, uses a giant PE overlay to evade scanners and deliver infostealers like Lumma, Vidar, and StealC.
securityonline.info
June 18, 2026 at 11:01 PM
GoFlateLoader: Il malware da 950 MB che mette in crisi antivirus e sandbox

📌 Link all'articolo : www.redhotcyber.com/post/goflate...

A cura di Luigi Zullo

#redhotcyber #news #goflate #malware #cybersecurity #hacking #golang #downloader
June 19, 2026 at 7:28 AM
GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers
GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers
A new malware loader called GoFlateLoader has been quietly spreading across the internet, and what makes it stand out is not how complex it is but how effective a simple trick has made it. Written in the Go programming language, this loader has one job: to decode and drop dangerous information-stealing programs onto a victim’s computer without being caught. It does this not through advanced hacking techniques but by making itself too large for most security tools to scan. GoFlateLoader has been actively distributed since at least April 2026, and in that short time it has already impacted more than 33,000 unique users globally. Countries most affected include Brazil, India, Argentina, Mexico, Turkey, and Spain, painting a picture of a broad and ongoing campaign that shows no signs of slowing down. The loader has been seen delivering several well-known infostealers , including Lumma, Vidar, StealC, Amatera, Remus, and SvitStealer. Researchers at Gen Digital identified and have been actively tracking GoFlateLoader, noting that it stands out precisely because of what it lacks. As Gen Digital said in a report  shared with Cyber Security News (CSN), the loader carries no anti-debugging checks, no virtual machine detection, and no sandbox-evasion logic, tools that most loaders use as a matter of course. Instead, it leans on one deceptively simple method to stay off the radar. The two main ways GoFlateLoader reaches victims are through fake cracked software downloads and through a malicious traffic distribution system recently documented by Check Point Research. In that second path, victims are redirected to a landing page showing a password-protected archive along with the password to open it, displayed separately. This separation makes it harder for security tools to automatically unpack and scan what is inside. Once the loader runs, it decodes its payload entirely within the computer’s memory, meaning the final malicious program never gets written to the hard drive. This in-memory approach is a known tactic used to avoid detection by security software that monitors file activity on disk. The use of Go’s syscall.Syscall function as a transfer mechanism, with hardcoded dummy arguments, is an unusual behavioral pattern that researchers say could serve as a useful detection marker. GoFlateLoader Uses Massive PE Overlay GoFlateLoader’s defining feature is its file size, which typically ranges between 700 and 950 megabytes. This enormous size is not accidental. GoFlateLoader’s execution flow (Source – Gen Digital) The loader artificially inflates itself by appending a large block of data, known as a PE overlay, to the end of the actual executable code. In most observed samples, this extra data is simply null bytes, though some builds use random padding instead. Structure of a GoFlateLoader sample highlighting a massive PE overlay (Source – Gen Digital) The goal of this inflation is straightforward. Many antivirus engines, endpoint detection tools, and cloud-based analysis platforms enforce strict size limits for files they are willing to deeply scan. VirusTotal, one of the most widely used threat intelligence platforms, enforces a 650 MB upload limit. GoFlateLoader’s consistent size just above that threshold strongly suggests it was built specifically to slip past VirusTotal and similar size-constrained tools. When compressed for distribution, the inflated data shrinks dramatically, making delivery fast and low-cost for attackers. Payloads Delivered and the Threat They Pose The final payloads GoFlateLoader delivers are all information stealers, programs designed to quietly harvest saved passwords, browser data, and cryptocurrency wallet credentials from infected machines. GoFlateLoader’s PE overlay filled with null bytes (Source – Gen Digital) The most common payloads observed are Amatera, Remus, and Lumma, with Vidar, StealC, and SvitStealer also seen in the wild. The loader comes in both 32-bit and 64-bit versions, each matched to the architecture of the payload it is meant to run. Users can reduce their risk by avoiding downloads from unofficial or untrusted sources, especially software advertised as cracked or free versions of paid programs. Keeping security tools updated and using solutions capable of detecting in-memory threats rather than relying solely on file scanning is strongly advised. Since GoFlateLoader avoids writing payloads to disk entirely, traditional file-based detection alone is unlikely to catch it. Indicators of Compromise (IoCs):- Type Indicator Description SHA-256 b88c5744975d2abb447aecc6c090fee9f8580413f4612eecdc6ed1973e8a1739 Password-protected archive containing GoFlateLoader x64 variant loading Remus (pwd: 1234) SHA-256 ed5ae7f36453c5a23e9868a5729d67e0549a11f6dea54f5f52d654a8f51d4902 Archive containing GoFlateLoader x64 variant loading Remus SHA-256 841c9297cb8a2e0ff89433d13c05bfc760eb2e98e251cb8fa785d2ad7cbac05f Archive containing GoFlateLoader x86 variant loading Amatera SHA-256 ece7c48eb411b24f26762ede83badb4a644c41d5777129381ac2541804d64fc2 Archive containing GoFlateLoader x86 variant loading Lumma SHA-256 421ce2d2f49c23bbe9f60ef3b9cd38d7eb912ce02e56a61837656210069bd9e2 Archive containing GoFlateLoader x64 variant loading Vidar SHA-256 121c2dc793b3873f75a29ec02241f94136de19c049382a50a50d0d5b99507073 GoFlateLoader x64 variant loading StealC SHA-256 2415db5081cec9bfd14ad6da1a66169fd96f13a49010c319a73d1ed6fafd4efa GoFlateLoader x64 variant loading Vidar SHA-256 d9917ade3b4c125a95b5d3e6343cde26145dfbf569bd7e2a843fd0c6fc8ddc28 GoFlateLoader x64 variant loading Remus SHA-256 4cf6893756f441522b94b36f10e5de0e47aeed4743f95c51650746d1ecf97e3d GoFlateLoader x64 variant loading SvitStealer SHA-256 8b89d6c9152d3aab97aadd515ecb69ca72654db2f25425759ba4b646853d737d GoFlateLoader x86 variant loading Lumma SHA-256 90ce4ff9da23ac150da0a8e17930cab1e369aa349fdc1b65691b70369145664a GoFlateLoader x86 variant loading Amatera Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers appeared first on Cyber Security News .
cybersecuritynews.com
June 11, 2026 at 6:04 PM
📢 GoFlateLoader : un loader Go répandu livrant plusieurs infostealers via overlay PE gonflé
📝 📅 **Source** : Gen Digital Blog (gendigital.com), publ…
https://cyberveille.ch/posts/2026-06-13-goflateloader-un-loader-go-repandu-livrant-plusieurs-infostealers-via-overlay-pe-gonfle/ #Amatera #Cyberveille
June 13, 2026 at 9:00 PM
GoFlateLoader’s Massive Malware Trick: How a 950MB Threat Silently Infected More Than 33,000 Victims Worldwide + Video

Introduction: When Bigger Means More Dangerous Cybercriminals are often associated with sophisticated exploits, zero-day vulnerabilities, and highly advanced attack chains. Yet…
GoFlateLoader’s Massive Malware Trick: How a 950MB Threat Silently Infected More Than 33,000 Victims Worldwide + Video
Introduction: When Bigger Means More Dangerous Cybercriminals are often associated with sophisticated exploits, zero-day vulnerabilities, and highly advanced attack chains. Yet some of the most successful malware campaigns prove that simplicity can be just as effective as innovation. A newly analyzed malware loader known as GoFlateLoader demonstrates this reality by using an unusually straightforward technique: making itself so large that many automated security systems struggle to analyze it.
undercodenews.com
June 12, 2026 at 10:05 AM
Cyber Threat Escalation: GoFlateLoader Loader Campaign and APT28 Evolution Toward Cloud C2 and LLM-Driven Infostealers + Video

Introduction: Rising Complexity in Modern Cyber Espionage and Malware Delivery The cybersecurity landscape continues to evolve at a rapid and alarming pace, with attackers…
Cyber Threat Escalation: GoFlateLoader Loader Campaign and APT28 Evolution Toward Cloud C2 and LLM-Driven Infostealers + Video
Introduction: Rising Complexity in Modern Cyber Espionage and Malware Delivery The cybersecurity landscape continues to evolve at a rapid and alarming pace, with attackers shifting from traditional malware frameworks to highly dynamic, modular, and stealth-driven infrastructures. Recent threat intelligence highlights two major developments: the emergence of GoFlateLoader, a Golang-based loader designed for in-memory execution of infostealers, and the long-term strategic evolution of APT28, a state-aligned threat actor adapting to cloud-based command systems and AI-assisted intrusion techniques.
undercodenews.com
June 11, 2026 at 4:54 PM
APT28 Evolves Into Cloud-Driven Espionage Era While GoFlateLoader Pushes Silent Infostealer Infections Across Global Targets + Video

Introduction: The New Face of a Two-Decade Cyber Conflict Cyber warfare is no longer defined by static malware or predictable intrusion tools. The latest…
APT28 Evolves Into Cloud-Driven Espionage Era While GoFlateLoader Pushes Silent Infostealer Infections Across Global Targets + Video
Introduction: The New Face of a Two-Decade Cyber Conflict Cyber warfare is no longer defined by static malware or predictable intrusion tools. The latest intelligence points to a dramatic transformation in the operations of APT28, also known as Fancy Bear, a threat actor long associated with advanced persistent espionage campaigns targeting Ukraine, NATO members, and critical infrastructure worldwide. What once relied on tools like X-Agent and X-Tunnel has now evolved into a fluid ecosystem of disposable modules, cloud-based command infrastructure, and even LLM-assisted infostealer development.
undercodenews.com
June 11, 2026 at 4:54 PM
GoFlateLoader Malware: The Silent Giant Proving That Simplicity Can Defeat Cybersecurity at Scale + Video

Introduction: A New Era of “Simple but Dangerous” Malware In today’s cybersecurity battlefield, complexity is no longer a requirement for devastation. Modern threat actors are increasingly…
GoFlateLoader Malware: The Silent Giant Proving That Simplicity Can Defeat Cybersecurity at Scale + Video
Introduction: A New Era of “Simple but Dangerous” Malware In today’s cybersecurity battlefield, complexity is no longer a requirement for devastation. Modern threat actors are increasingly shifting away from heavily obfuscated, highly engineered malware and embracing something far more dangerous in its simplicity. GoFlateLoader is a perfect example of this evolution. Written in Go and designed with minimal sophistication, it demonstrates how attackers can bypass advanced defenses not by outsmarting them with complexity, but by exploiting operational blind spots in security infrastructure.
undercodenews.com
June 11, 2026 at 1:25 PM
GoFlateLoader uses Massive PE Overlay to deliver Lumma, Vidar, and StealC Infostealers:

cybersecuritynews.com/goflateloade...
June 13, 2026 at 9:12 AM
GoFlateLoader evades detection with a massive PE overlay, deploying infostealers like Lumma and Vidar. #GoFlateLoader #Malware #CyberSecurity #Infostealer #Lumma #Vidar #PEOverlay #ThreatDetection thedailytechfeed.com/goflateloade...
June 11, 2026 at 5:23 PM
GoFlateLoaderマルウェアローダー:GolangベースのInfostealer脅威

悪意あるソフトウェアを隠蔽する最も単純な手法は、巧妙なカモフラージュではなく、過剰なデジタルサイズによるものである場合があります。GoFlateLoaderはまさにこの手法を活用しています。これはGolangで実装されたローダーであり、Lumma、Vidar、StealC、Amatera、Remu...
GoFlateLoaderマルウェアローダー:GolangベースのInfostealer脅威
悪意あるソフトウェアを隠蔽する最も単純な手法は、巧妙なカモフラージュではなく、過剰なデジタルサイズによるものである場合があります。GoFlateLoaderはまさにこの手法を活用しています。これはGolangで実装されたローダーであり、Lumma、Vidar、StealC、Amatera、Remu
blackhatnews.tokyo
June 15, 2026 at 2:35 AM
GoFlateLoaderがクラックソフトウェアと悪意あるTDSキャンペーンを通じて拡散

最も効果的なマルウェアは、技術的な洗練さよりも力技に頼ることがあります。GoFlateLoaderはGo言語で書かれたシンプルなインメモリローダーであり、ファイルサイズを意図的に膨張させることでセキュリティスキャナーを回避します。 高度なアンチデバッグ・アンチVM・サンドボックス回避技術を持たないにもかかわらず、20
GoFlateLoaderがクラックソフトウェアと悪意あるTDSキャンペーンを通じて拡散
最も効果的なマルウェアは、技術的な洗練さよりも力技に頼ることがあります。GoFlateLoaderはGo言語で書かれたシンプルなインメモリローダーであり、ファイルサイズを意図的に膨張させることでセキュリティスキャナーを回避します。 高度なアンチデバッグ・アンチVM・サンドボックス回避技術を持たないにもかかわらず、20
blackhatnews.tokyo
June 12, 2026 at 9:56 AM
GoFlateLoader:巨大PEオーバーレイに潜む情報窃取型マルウェア

GoFlateLoaderは、Lumma、Vidar、StealC、Amatera、Remusをはじめとする複数の情報窃取マルウェア(インフォスティーラー)の主要な配布手段として広く利用されているGolang製ローダーです。 GoFlateLoaderの設計は意図的にシンプルで、コードはメモリ上で動作する単純なマニュ...
GoFlateLoader:巨大PEオーバーレイに潜む情報窃取型マルウェア
GoFlateLoaderは、Lumma、Vidar、StealC、Amatera、Remusをはじめとする複数の情報窃取マルウェア(インフォスティーラー)の主要な配布手段として広く利用されているGolang製ローダーです。 GoFlateLoaderの設計は意図的にシンプルで、コードはメモリ上で動作する単純なマニュ
blackhatnews.tokyo
June 11, 2026 at 1:29 PM
GoFlateLoaderマルウェア、Lumma・Vidar・StealCなどのペイロードを投下

脅威アクターたちは、マルウェアが高度に洗練されていなくても絶大な効果を発揮できることを証明し続けています。GoFlateLoaderマルウェアは、こうした傾向を端的に示す好例です。 Go言語で書かれたこのシンプルなローダーの目的はただ一つ、悪意あるペイロードをコンピュータのメモリ上で直接デコードして実行することです。
GoFlateLoaderマルウェア、Lumma・Vidar・StealCなどのペイロードを投下
脅威アクターたちは、マルウェアが高度に洗練されていなくても絶大な効果を発揮できることを証明し続けています。GoFlateLoaderマルウェアは、こうした傾向を端的に示す好例です。 Go言語で書かれたこのシンプルなローダーの目的はただ一つ、悪意あるペイロードをコンピュータのメモリ上で直接デコードして実行することです。
blackhatnews.tokyo
June 11, 2026 at 12:52 PM
Blog: "GoFlateLoader usa superposición PE masiva para distribuir Lumma, Vidar y StealC"
GoFlateLoader usa superposición PE masiva para distribuir Lumma, Vidar y StealC
Blog sobre informática, tecnología y seguridad con manuales, tutoriales y documentación sobre herramientas y programas
blog.elhacker.net
June 13, 2026 at 4:02 AM
Gen Threat Labs researcher Vojtěch Krejsa looks into GoFlateLoader, a widespread Golang loader used to deliver multiple infostealers, including Amatera, Remus, Lumma, Vidar and StealC. www.gendigital.com/blog/insight...
June 11, 2026 at 10:08 AM
The GoFlateLoader malware, active since April 2026, uses an extremely simple evasion tactic: artificially inflating its file size to 700-950 MB just above the 650 MB upload limit on platforms like VirusTotal.
June 18, 2026 at 9:46 AM