Remus
According to Gen, this is most likely the 64bit evolution of Lumma Stealer. It is capable of stealing stored browser passwords, cookies, cryptocurrency, and much more. It also uses EtherHiding to resolve C2s, replacing the traditional use of Steam and Telegram dead drop resolvers, and has additional anti-analysis checks.
C2 Infrastructure
Hosting/VPS64%
ISP/Residential36%
Last 7 days
May 15, 2026
C2 Hosts: 6
May 14, 2026
C2 Hosts: 8
| Date | C2 Hosts |
|---|---|
| May 15, 2026 | 6 |
| May 14, 2026 | 8 |