Skip to content

Remus

Remus is a Windows information stealer distributed through SEO-poisoned websites impersonating cracked software and pirated games, with campaigns using Turkish-language lures.

Profile source: Mallory opens in a new tab

Remus

Family profile

Remus is a Windows information stealer distributed through SEO-poisoned websites impersonating cracked software and pirated games, with campaigns using Turkish-language lures. It has also been deployed through ClickFix social-engineering chains in which victims are induced to execute malicious PowerShell commands, including campaigns using the ErrTraffic delivery service and Cruciferra loader. Remus injects into Chromium-based browser processes to obtain browser vault data and collects saved credentials, session cookies, browsing data, cryptographic-wallet extension data, password-manager data, gaming-platform artifacts, FTP credentials, clipboard contents, screenshots, enterprise email storage, and host information. It targets locally stored artifacts from Claude, Cursor, and OpenCode, which can include authentication tokens, configuration data, and development context. Remus resolves active command-and-control infrastructure through an Ethereum smart contract, facilitating backend rotation, and exfiltrates collected information over HTTP POST while disguising traffic with spoofed request headers. It can retrieve browser encryption material and enable offline decryption of stolen browser secrets. The malware is commonly delivered through shared fake-software distribution infrastructure alongside other infostealer families.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Process Injection
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 13, 2026
Feed role
C2 / Distribution
Host form
43 IP / 155 hostnames

Leading locations

  • US66
  • DE30
  • CN8
  • FR8
  • NL7
  • BR5
  • IN5
  • IE4
  • IT4
  • BE3
  • GB3
  • KR3

Leading providers

  • DigitalOcean, LLC13
  • Amazon.com, Inc.11
  • OVH SAS11
  • Cloudflare, Inc.9
  • Hostinger International Limited9
  • Amazon.com, Inc.8

Infrastructure traits

  • Hosting 156
  • Anycast 10
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
ErrTraffic

The loader then uses process hollowing to place the Remus stealer inside ServiceModelReg.exe.

MITRE ATT&CK

Remus in ATT&CK

46 distinct techniques

Reporting

Research mentioning Remus

Aug 19
Infosecurity Magazine News

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra - Infosecurity Magazine

Late-July campaigns used the ErrTraffic malware-as-a-service platform and ClickFix social engineering to lure victims from compromised WordPress sites into running malicious PowerShell copied to their clipboard. The infection chain fetched fake verification pages, resolved command-and-control through Polygon smart contracts, and used DLL side-loading before hollowing the Remus information stealer into the legitimate Microsoft-signed binary ServiceModelReg.exe. The Cruciferra loader provided the campaignโ€™s defense-evasion capability by abusing the signed but vulnerable DCRCVDrv.sys driver in a bring-your-own-vulnerable-driver attack to terminate antivirus and EDR processes at kernel level. Researchers said Cruciferra is marketed separately as a MaaS offering, with higher-tier options for UAC bypass and EDR killing, while ErrTraffic is sold as a delivery service with customizable lures and campaign management, showing how operators can combine modular criminal services to distribute infostealers and disable endpoint protections.

Aug 19
Esentire

Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025 | eSentire

Aug 18
Gen Insights Research

Gen Blogs | WordlistLoader Delivering Amatera via ClearFake Campaigns

Researchers identified WordlistLoader as a new malware loader used in ClearFake campaigns to deliver Amatera Stealer (also tracked as ACR Stealer) through compromised legitimate websites. Victims are shown FakeCaptcha overlays and tricked into running clipboard-delivered commands that abuse conhost, cmd, WebDAV shares, and rundll32 to launch the loader. WordlistLoader then rebuilds shellcode from encoded English words or UUID fragments, unhooks modules, disables ETW logging with a hardware-breakpoint-based bypass, and executes shellcode that decrypts and reflectively loads Amatera. The campaign includes infrastructure such as command-and-control domains, dead-drop URLs, malware hashes, and compromised-site indicators. The activity also reflects a broader trend of commodity stealers adopting advanced Windows evasion methods more often associated with higher-end malware. Amateraโ€™s newer builds add stronger static obfuscation, stealthier WoW64 syscall invocation, and runtime-built x64 indirect syscall trampolines using Heavenโ€™s Gate, a technique previously documented as a way to bypass user-mode hooks in the WoW64 subsystem. Its updated Chromium Application-Bound Encryption bypass also resembles methods seen in Remus and Lumma, underscoring how infostealer operators are rapidly incorporating sophisticated anti-detection and credential-theft capabilities into large-scale web-injection campaigns.

Jul 15
Malware News

June 2026 Infostealer Trend Report - Malware Analysis - Malware Analysis, News and Indicators

ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.

Jul 14
Ahnlab Asec

June 2026 Infostealer Trend Report - ASEC

Aug 19
Safebreach

Process Injection Using Windows Thread Pools | Safebreach

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.