Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 13, 2026
- Feed role
- C2 / Distribution
- Host form
- 43 IP / 155 hostnames
Remus is a Windows information stealer distributed through SEO-poisoned websites impersonating cracked software and pirated games, with campaigns using Turkish-language lures.
Profile source: Mallory opens in a new tabRemus
Remus is a Windows information stealer distributed through SEO-poisoned websites impersonating cracked software and pirated games, with campaigns using Turkish-language lures. It has also been deployed through ClickFix social-engineering chains in which victims are induced to execute malicious PowerShell commands, including campaigns using the ErrTraffic delivery service and Cruciferra loader. Remus injects into Chromium-based browser processes to obtain browser vault data and collects saved credentials, session cookies, browsing data, cryptographic-wallet extension data, password-manager data, gaming-platform artifacts, FTP credentials, clipboard contents, screenshots, enterprise email storage, and host information. It targets locally stored artifacts from Claude, Cursor, and OpenCode, which can include authentication tokens, configuration data, and development context. Remus resolves active command-and-control infrastructure through an Ethereum smart contract, facilitating backend rotation, and exfiltrates collected information over HTTP POST while disguising traffic with spoofed request headers. It can retrieve browser encryption material and enable offline decryption of stolen browser secrets. The malware is commonly delivered through shared fake-software distribution infrastructure alongside other infostealer families.
C2 tracking
Derp observations, rolling seven-day window
Samples
865d76d478e2ccd75cec7e80f8b32053ba0a41f98e242e9b3316b74c9a7a9dd4 0408bdca641153370d5a0c58183271e2b38b576c2f6769b1772394ca2ab62132 080f6aa9f38497cc8cee9a32f00790f0093770052daec18a04b020bd05ebf433 0e5e672f3ee2499f8fe2d8f0c8a4c0e575344235092afcfabc0f4d3c0480e629 0f90f9b1c94e63147b67c14aecfe4549169b1259eb851527d411396cfb8bdffc 10b787bba8ed4d3e972870d34e48cc55c529e195d59002bbc806317d84a6225c 166141804064419f441f94d2177f5cf22e71c4ceeb98d277ee27fab1db519558 1a7d3b8073aeed1e2ce0a529cc460401640c4d29a8bd5118a13a3d6c8538851e 1b69363b9ed0850ee601e77129b99ff4a40b248dac82d6866757441c0d0c5172 223dc93eaedad30cb24a72fade4b1aefdc6990e498174b7fd7aed7bf16ad8d94 Reported operators
The loader then uses process hollowing to place the Remus stealer inside ServiceModelReg.exe.
MITRE ATT&CK
Reporting
Late-July campaigns used the ErrTraffic malware-as-a-service platform and ClickFix social engineering to lure victims from compromised WordPress sites into running malicious PowerShell copied to their clipboard. The infection chain fetched fake verification pages, resolved command-and-control through Polygon smart contracts, and used DLL side-loading before hollowing the Remus information stealer into the legitimate Microsoft-signed binary ServiceModelReg.exe. The Cruciferra loader provided the campaignโs defense-evasion capability by abusing the signed but vulnerable DCRCVDrv.sys driver in a bring-your-own-vulnerable-driver attack to terminate antivirus and EDR processes at kernel level. Researchers said Cruciferra is marketed separately as a MaaS offering, with higher-tier options for UAC bypass and EDR killing, while ErrTraffic is sold as a delivery service with customizable lures and campaign management, showing how operators can combine modular criminal services to distribute infostealers and disable endpoint protections.
Researchers identified WordlistLoader as a new malware loader used in ClearFake campaigns to deliver Amatera Stealer (also tracked as ACR Stealer) through compromised legitimate websites. Victims are shown FakeCaptcha overlays and tricked into running clipboard-delivered commands that abuse conhost, cmd, WebDAV shares, and rundll32 to launch the loader. WordlistLoader then rebuilds shellcode from encoded English words or UUID fragments, unhooks modules, disables ETW logging with a hardware-breakpoint-based bypass, and executes shellcode that decrypts and reflectively loads Amatera. The campaign includes infrastructure such as command-and-control domains, dead-drop URLs, malware hashes, and compromised-site indicators. The activity also reflects a broader trend of commodity stealers adopting advanced Windows evasion methods more often associated with higher-end malware. Amateraโs newer builds add stronger static obfuscation, stealthier WoW64 syscall invocation, and runtime-built x64 indirect syscall trampolines using Heavenโs Gate, a technique previously documented as a way to bypass user-mode hooks in the WoW64 subsystem. Its updated Chromium Application-Bound Encryption bypass also resembles methods seen in Remus and Lumma, underscoring how infostealer operators are rapidly incorporating sophisticated anti-detection and credential-theft capabilities into large-scale web-injection campaigns.
ASEC reported that infostealer activity observed in June was dominated by Remus, ACRStealer, LummaC2, and Vidar, which were commonly distributed through SEO-poisoned pages advertising cracks and keygens. The campaigns frequently used cloud-storage services such as Mediafire and Mega to host payloads, with Microsoft Corporation the most commonly impersonated brand in newly collected samples. Most infections relied on EXE payloads, while a smaller portion used DLL side-loading with files including python37.dll, LcMgr.dll, and python315.dll. The report also highlighted macOS-focused delivery using ClickFix lures and malicious Bash scripts, including a variant that pulled C2 addresses from Polygon smart contracts and established persistence through a LaunchAgent plist. In parallel email campaigns, AgentTesla and DarkCloud were sent in compressed attachments disguised as messages from Japanese and Indian companies, then used SMTP to exfiltrate stolen data. ASEC said the findings were based on malware gathered through its automated collection systems, email honeypot, and malware C2 analysis infrastructure.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.