Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 57 IP / 70 hostnames
Remus is a Windows infostealer that emerged in early 2026 and is widely assessed as a 64-bit evolutionary branch of Lumma Stealer.
Profile source: Mallory opens in a new tabRemus
Remus is a Windows infostealer that emerged in early 2026 and is widely assessed as a 64-bit evolutionary branch of Lumma Stealer. It focuses on theft of browser credentials, cookies, cryptocurrency-wallet data, and other locally stored secrets, while also expanding into session-oriented theft and malware-as-a-service operations. Reporting on its underground development indicates rapid maturation from a basic credential stealer into a commercialized platform emphasizing persistent authenticated access, restore-token abuse, operator dashboards, affiliate workflows, and Telegram-based log delivery.
Technically, Remus targets Chromium-based browsers and uses in-process access to recover protected browser secrets. It has been observed injecting into browser processes and using a Lumma-like Application-Bound Encryption bypass to locate and decrypt the browser master key from memory, enabling theft of saved passwords, cookies, and related vault data. If direct browser-process access fails, it can launch a hidden browser instance on a separate desktop. Beyond browser theft, observed capabilities include collection of cryptocurrency-wallet extension data, password-manager artifacts, FTP credentials, gaming-platform data, clipboard contents, screenshots, enterprise email storage files, and host profiling information.
A notable feature of Remus is its command-and-control resolution model. Rather than relying on a fixed server, some clusters use EtherHiding-style dead-drop resolution through Ethereum smart contracts queried over public JSON-RPC infrastructure, allowing operators to rotate backend infrastructure without changing the malware binary. Exfiltration has been observed over HTTP POST, with traffic disguised to resemble benign telemetry. Anti-analysis features reported for Remus include anti-virtualization checks and checks for sandbox or research-environment artifacts.
Remus is strongly associated with criminal distribution ecosystems centered on fake cracked-software and warez lures, including SEO-poisoned sites and malicious traffic-distribution systems. It has also appeared as a payload in ClickFix social-engineering chains and has been delivered by loaders such as GoFlateLoader, as well as in plugin form within SmokeLoader activity. Campaign reporting indicates frequent targeting of Windows users seeking pirated software, with some campaigns particularly focused on Turkish-language lures and Turkish users. The malware is financially motivated and fits the broader industrialized infostealer economy in which stolen credentials, cookies, and session artifacts are monetized through account takeover, fraud, resale, and follow-on intrusion activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6747147c5ba29975a557d88cd22114478890a0a0a613f36512dcb730e4efe965 944a6ff7edb3991a3f60e19d26f23ad21054adc53109cfcdbb5d101a84a7971b dd17e871204619a3de34126e366221b64e684ec13e24dfc871698abe343acbff fbf4ef28c4b49c6304d23a738afabf8981590eae8585834bf24e3c7e87163c1a 67cd5f1b19d33786a9f73b630357cce0d90d6771590ccb965fb331ffc6d4fb94 73fc2d3057331b8382c4e0e833f495c2843bfb36a48d7e765ddbc1be241e5a67 d2555e5f817810e4839bb5c163514cf4807b5f9878708a519d68e52f5d48e7ab dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 f1fe7bb2031c73328ccb32730d319b8ba0dabca108addd1135468a75fed36b8f MITRE ATT&CK
Reporting
ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.