Skip to content

Remus

Remus is a Windows infostealer that emerged in early 2026 and is widely assessed as a 64-bit evolutionary branch of Lumma Stealer.

Profile source: Mallory opens in a new tab

Remus

Family profile

Remus is a Windows infostealer that emerged in early 2026 and is widely assessed as a 64-bit evolutionary branch of Lumma Stealer. It focuses on theft of browser credentials, cookies, cryptocurrency-wallet data, and other locally stored secrets, while also expanding into session-oriented theft and malware-as-a-service operations. Reporting on its underground development indicates rapid maturation from a basic credential stealer into a commercialized platform emphasizing persistent authenticated access, restore-token abuse, operator dashboards, affiliate workflows, and Telegram-based log delivery.

Technically, Remus targets Chromium-based browsers and uses in-process access to recover protected browser secrets. It has been observed injecting into browser processes and using a Lumma-like Application-Bound Encryption bypass to locate and decrypt the browser master key from memory, enabling theft of saved passwords, cookies, and related vault data. If direct browser-process access fails, it can launch a hidden browser instance on a separate desktop. Beyond browser theft, observed capabilities include collection of cryptocurrency-wallet extension data, password-manager artifacts, FTP credentials, gaming-platform data, clipboard contents, screenshots, enterprise email storage files, and host profiling information.

A notable feature of Remus is its command-and-control resolution model. Rather than relying on a fixed server, some clusters use EtherHiding-style dead-drop resolution through Ethereum smart contracts queried over public JSON-RPC infrastructure, allowing operators to rotate backend infrastructure without changing the malware binary. Exfiltration has been observed over HTTP POST, with traffic disguised to resemble benign telemetry. Anti-analysis features reported for Remus include anti-virtualization checks and checks for sandbox or research-environment artifacts.

Remus is strongly associated with criminal distribution ecosystems centered on fake cracked-software and warez lures, including SEO-poisoned sites and malicious traffic-distribution systems. It has also appeared as a payload in ClickFix social-engineering chains and has been delivered by loaders such as GoFlateLoader, as well as in plugin form within SmokeLoader activity. Campaign reporting indicates frequent targeting of Windows users seeking pirated software, with some campaigns particularly focused on Turkish-language lures and Turkish users. The malware is financially motivated and fits the broader industrialized infostealer economy in which stolen credentials, cookies, and session artifacts are monetized through account takeover, fraud, resale, and follow-on intrusion activity.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
57 IP / 70 hostnames

Leading locations

  • US32
  • DE17
  • CN11
  • LU11
  • NL8
  • FR6
  • RU6
  • IE4
  • PL4
  • BR3
  • SG3
  • BA2

Leading providers

  • Ghosty Networks LLC12
  • Amazon.com, Inc.9
  • Amazon.com, Inc.9
  • Contabo GmbH4
  • DEDIK SERVICES LIMITED4
  • DigitalOcean, LLC4

Infrastructure traits

  • Hosting 106
  • Vpn 6
  • Residential Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

Remus in ATT&CK

43 distinct techniques

Reporting

Research mentioning Remus

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.