Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 30, 2026
- Feed role
- C2 / Distribution
- Host form
- 75 IP / 63 hostnames
Remus is a 64-bit Windows infostealer assessed as an evolutionary branch of the Lumma Stealer ecosystem and operated as a malware-as-a-service offering.
Profile source: Mallory opens in a new tabRemus
Remus is a 64-bit Windows infostealer assessed as an evolutionary branch of the Lumma Stealer ecosystem and operated as a malware-as-a-service offering. It emerged in early 2026 after transitional test builds known as Tenzor and rapidly developed from a browser credential stealer into a broader platform focused on persistent authenticated access, session theft, and scalable criminal operations. Underground marketing emphasized subscription-style access, operator support, delivery workflows, restore-token features, statistics, and affiliate-oriented management, reflecting a mature commercialized stealer ecosystem.
Remus is designed to steal browser passwords, cookies, authentication tokens, cryptocurrency wallet data, clipboard contents, screenshots, and system profiling information. Reported functionality also includes collection of browser extension and IndexedDB artifacts associated with password managers such as 1Password, LastPass, and Bitwarden-related data, although direct vault decryption has not been independently confirmed. The malware increasingly emphasized session hijacking and restore workflows to preserve access and bypass defenses such as MFA and risk-based authentication. It has also been associated with theft targeting platforms including Discord, Steam, Riot Games, and Telegram for monetization through account resale, fraud, and follow-on abuse.
Technically, Remus shares multiple distinctive traits with Lumma, including similar string obfuscation, anti-virtualization checks, direct syscall usage, indirect control-flow obfuscation, ChaCha20-protected configuration storage, and a highly specific Chromium Application-Bound Encryption bypass. To recover protected browser secrets, Remus injects shellcode into a live browser process to locate and decrypt the Chromium v20 master key from memory using the browserβs own decryption context. If injection fails or no suitable browser process exists, it can launch a hidden browser instance on a separate desktop with a randomized name to continue extraction. Remus also incorporates anti-analysis checks for sandbox and research environments.
Command-and-control resolution has been observed using EtherHiding, with runtime retrieval of infrastructure from Ethereum smart contracts rather than relying solely on static configuration. Researchers have also documented blockchain-backed dead-drop resolver clusters and broader infrastructure patterns consistent with automated operations. Remus has been delivered through several criminal distribution ecosystems, including SEO-poisoned cracked-software and keygen lures, ClickFix social-engineering campaigns using fake verification pages, malicious traffic distribution systems, and loaders such as GoFlateLoader. It has also appeared as a plugin payload in SmokeLoader-related activity. Observed campaigns indicate broad victim targeting across individual and enterprise users, with financially motivated objectives centered on credential theft, session abuse, and downstream account compromise.
C2 tracking
Derp observations, rolling seven-day window
Samples
514a69a890324fc24cddd888370092687a061479f8b5d28cd002ca792b5d8ede 5459c708a6b6a6bfbbc7e28b668fcbb1a18138abb758244fa15d74d3216dfa3a 8a6aa2241f1d1efc8b7a6d79a6139da6ed237769424e7d1a49b3f18a34bd2b9f 8a8857de50c2170ca7af40786168a6526e8190e297ec55e3d6a71fbfd21c3b17 bbdef8d9fe0f2c13be5a5332f881700d131d6782468ba0320aec8a76486dd441 6f26a68fabce865b6461a031fd3a18ecaa26d5ab9b8fb5002feeb97ba966392c a475b6c040a8f6a8857098f65325293f21c2aa120ce7b613a94973516b0909c2 1f49316f60cee5fd365ecda4b1c43fcfe10ec5a52fd0721b4eeb811afeab77ba 4c0d2372f3d03a95fae67956989fbc9e307b318c5551f74a48c2b850d55bb169 cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c MITRE ATT&CK
Reporting
ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.