Skip to content

Remus

Remus is a 64-bit Windows infostealer assessed as an evolutionary branch of the Lumma Stealer ecosystem and operated as a malware-as-a-service offering.

Profile source: Mallory opens in a new tab

Remus

Family profile

Remus is a 64-bit Windows infostealer assessed as an evolutionary branch of the Lumma Stealer ecosystem and operated as a malware-as-a-service offering. It emerged in early 2026 after transitional test builds known as Tenzor and rapidly developed from a browser credential stealer into a broader platform focused on persistent authenticated access, session theft, and scalable criminal operations. Underground marketing emphasized subscription-style access, operator support, delivery workflows, restore-token features, statistics, and affiliate-oriented management, reflecting a mature commercialized stealer ecosystem.

Remus is designed to steal browser passwords, cookies, authentication tokens, cryptocurrency wallet data, clipboard contents, screenshots, and system profiling information. Reported functionality also includes collection of browser extension and IndexedDB artifacts associated with password managers such as 1Password, LastPass, and Bitwarden-related data, although direct vault decryption has not been independently confirmed. The malware increasingly emphasized session hijacking and restore workflows to preserve access and bypass defenses such as MFA and risk-based authentication. It has also been associated with theft targeting platforms including Discord, Steam, Riot Games, and Telegram for monetization through account resale, fraud, and follow-on abuse.

Technically, Remus shares multiple distinctive traits with Lumma, including similar string obfuscation, anti-virtualization checks, direct syscall usage, indirect control-flow obfuscation, ChaCha20-protected configuration storage, and a highly specific Chromium Application-Bound Encryption bypass. To recover protected browser secrets, Remus injects shellcode into a live browser process to locate and decrypt the Chromium v20 master key from memory using the browser’s own decryption context. If injection fails or no suitable browser process exists, it can launch a hidden browser instance on a separate desktop with a randomized name to continue extraction. Remus also incorporates anti-analysis checks for sandbox and research environments.

Command-and-control resolution has been observed using EtherHiding, with runtime retrieval of infrastructure from Ethereum smart contracts rather than relying solely on static configuration. Researchers have also documented blockchain-backed dead-drop resolver clusters and broader infrastructure patterns consistent with automated operations. Remus has been delivered through several criminal distribution ecosystems, including SEO-poisoned cracked-software and keygen lures, ClickFix social-engineering campaigns using fake verification pages, malicious traffic distribution systems, and loaders such as GoFlateLoader. It has also appeared as a plugin payload in SmokeLoader-related activity. Observed campaigns indicate broad victim targeting across individual and enterprise users, with financially motivated objectives centered on credential theft, session abuse, and downstream account compromise.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Reconnaissance
  • Session Hijacking

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 30, 2026
Feed role
C2 / Distribution
Host form
75 IP / 63 hostnames

Leading locations

  • US28
  • DE22
  • FR14
  • NL12
  • LU10
  • PL7
  • SG5
  • BR3
  • CA3
  • CN3
  • JP3
  • RU3

Leading providers

  • Cloudflare, Inc.11
  • Contabo GmbH11
  • Ghosty Networks LLC11
  • DigitalOcean, LLC8
  • DEDIK SERVICES LIMITED6
  • FEMO IT SOLUTIONS LIMITED5

Infrastructure traits

  • Hosting 123
  • Anycast 14
  • Vpn 3
  • Residential Proxy 2
  • Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

Remus in ATT&CK

39 distinct techniques

Reporting

Research mentioning Remus

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.