Skip to content

Remus

According to Gen, this is most likely the 64bit evolution of Lumma Stealer. It is capable of stealing stored browser passwords, cookies, cryptocurrency, and much more. It also uses EtherHiding to resolve C2s, replacing the traditional use of Steam and Telegram dead drop resolvers, and has additional anti-analysis checks.

C2 Infrastructure

Hosting/VPS64%
ISP/Residential36%

Last 7 days

May 15, 2026
C2 Hosts: 6
May 14, 2026
C2 Hosts: 8