Gremlin Stealer Evolves into Modular Threat with Advanced Evasion Capabilities

2026-05-15T14:52:28Z86e90945150dbdc4fcb5ed2b08e35a689993ef592ca056e64df952fb00895d06
avada builderbeagle backdoorchina‑linkeddata‑stealerdirty fragdonutloaderexchange zero‑dayfake‑Claudefdmtp backdoorfile readfragnesiagremlin stealerlinux kernellocal privilege escalationmalwaremicrosoft exchangemustang pandanpm/pyPI supply‑chainsql injectionsupply chain compromisetencshelltyposquatvidar infostealerwordpresszero‑day

What happened

Infosecurity Magazine roundup highlights multiple high-risk threats and vulnerabilities: a new modular Gremlin stealer with advanced evasion and data-theft capabilities; a severe Microsoft zero-day affecting on‑prem Exchange Server (2016, 2019 and Subscription Edition); new China‑linked TencShell malware and Mustang Panda’s updated FDMTP backdoor targeting APJ; and fresh Linux kernel escalation flaws (Fragnesia and related ‘Dirty Frag’ issues). Significant supply‑chain and tooling abuse is reported — Avada Builder flaws exposing ~1M WordPress sites (file‑read/SQLi), npm/PyPI compromise (Mini‑S

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
86e90945150dbdc4fcb5ed2b08e35a689993ef592ca056e64df952fb00895d06
Enrichment time
2026-05-15T14:52:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.