Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Remus Stealer

27
Global rank
11 infographic chevron month
Month rank
11
Week rank
0
IOCs

Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

Stealer
Type
Unknown
Origin
1 February, 2026
First seen
5 September, 2026
Last seen

How to analyze Remus Stealer with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
5 September, 2026
Last seen

IOCs

IP addresses
104.21.43.2
142.251.155.4
188.114.96.3
72.246.29.11
48.209.133.15
48.209.138.168
40.126.32.138
142.251.127.84
23.11.206.99
104.17.24.14
172.217.119.4
154.19.37.231
23.52.181.141
157.240.253.1
23.11.41.157
92.113.23.131
35.190.80.1
92.113.16.150
172.67.176.45
142.251.14.101
Hashes
c4596b16b126326b0d8fc2fb8bf91389ad3dc4671a269187913c19a8f2ad1094
ea420d765b3a2def39c1b5ae6ec17b209cd156ab21fa8a8716159bb05ed655e7
d5ecd1f39b078601a06dff9e9f62474551db346e6791f89e7ea4c4df32bf02d5
afe7e1b89e41b41fb0d129846b0fd9b65b2b57891ffd0502d7ab777502defffd
4dce1f7130cae19886f5306a8277b041508966c6d5144bad2b9ff62344e74969
06bac0948d4f8fa4de448d65577b8fecb39036c97614919dc56ed53d0f574195
39f94024cbcf740958d8bb6e25095e33ee260776744698ff4e0d43a4454bf72f
207993b30364d0f292d540615e81c3bd139fc1ff37bfaa9b31c0b9aba06f13f4
fda3c6bf555467c120fe124c87439cf3348ea1814693cb2394e52ee1153beff7
c5f3b2f654d2d8210a481c0164f0a53430cd09b77c34374fe23c9a03f5ad00fb
768a94f6b4c3ddc1c5e0faee9a92f7cb24f0c468a9891721d71973ba334097ef
9af77ff87c6e8ee5446846ce801c3adaf9ea87f66bab96a80470b112ed5a32ca
6ae7f2b09995ae0dfba615f3d3233d89d8024882d0e14aba562c91379f975bf6
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
Domains
www.facebook.com
slscr.update.microsoft.com
cdn.popt.in
cdnjs.cloudflare.com
settings-win.data.microsoft.com
ocsp.digicert.com
fonts.googleapis.com
interseqf.com
crl.microsoft.com
th.bing.com
alameda-hc.com
fe3cr.delivery.mp.microsoft.com
connect.facebook.net
mypopups.com
safebrowsingohttpgateway.googleapis.com
oneocsp.microsoft.com
www.bing.com
optimizationguide-pa.googleapis.com
login.live.com
www.youtube.com
URLs
http://clients2.google.com/time/1/current?cup2key=8:bn7sgp8yumujuzmrfine6d9w-nntyv7-jolgp2sy2m0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://alameda-hc.com/
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://alameda-hc.com/
https://alameda-hc.com/wp-includes/css/dist/block-library/style.min.css?ver=7.0.2
https://alameda-hc.com/wp-content/themes/ekko/core/assets/css/bootstrap.min.css?ver=3.7
https://alameda-hc.com/wp-content/themes/ekko/style.css?ver=3.7
https://alameda-hc.com/wp-content/plugins/keydesign-addon/assets/css/kd_vc_front.css?ver=7.0.2
https://alameda-hc.com/wp-content/plugins/menu-image/includes/css/menu-image.css?ver=3.13
https://alameda-hc.com/wp-includes/css/dashicons.min.css?ver=7.0.2
https://alameda-hc.com/wp-content/plugins/page-list/css/page-list.css?ver=6.3
https://alameda-hc.com/wp-content/plugins/preloader-plus/assets/css/preloader-plus.min.css?ver=2.2.1
https://alameda-hc.com/wp-content/plugins/wpguppy-lite/chatapp/dist/css/app.css?ver=1.1.6
https://alameda-hc.com/wp-content/plugins/wpguppy-lite/chatapp/dist/css/vendors.css?ver=1.1.6
https://alameda-hc.com/wp-content/plugins/wpguppy-lite/public/css/guppy-icons.css?ver=1.1.6
https://alameda-hc.com/wp-content/plugins/translatepress-multilingual/assets/css/trp-language-switcher.css?ver=3.2.2
https://alameda-hc.com/wp-content/themes/ekko/core/assets/css/ekko-font.css?ver=3.7
https://alameda-hc.com/wp-content/plugins/redux-framework/redux-core/inc/extensions/social_profiles/social_profiles/css/field_social_profiles_frontend.css?ver=4.5.8
Last Seen at

Recent blog posts

post image
Release Notes: Faster TI Investigations, Fres...
watchers 2830
comments 0
post image
Triage & Response Bottlenecks Eating into...
watchers 2877
comments 0
post image
Major Cyber Attacks in August 2026: US and EU...
watchers 8121
comments 0

From Lumma’s Ashes: Remus Stealer Uses Blockchain to Steal Your Business Data

Key Takeaways

  • Remus Stealer is a rapidly evolving Malware-as-a-Service infostealer that emerged in 2026.
  • It utilizes EtherHiding, storing C2 addresses in Ethereum smart contracts to avoid takedowns.
  • The malware steals credentials, browser cookies, authentication tokens, and cryptocurrency wallet data.
  • Session theft is one of Remus's most dangerous capabilities because it can bypass MFA by stealing active session cookies directly from browser memory.
  • The malware shows strong technical similarities to Lumma Stealer and may represent its evolutionary successor.
  • Financial services, healthcare, government, technology firms, and MSPs are particularly attractive targets.
  • Common infection vectors include phishing, fake software downloads, malvertising, and fake CAPTCHA campaigns, as well as SEO poisoning and fake GitHub projects to trick tech-savvy users.
  • ANY.RUN's Threat Intelligence Feeds and Threat Intelligence Lookup help defenders proactively identify Remus-related infrastructure, hunt for indicators of compromise, and strengthen detection coverage before attacks escalate.

Pivot from Remus IOCs to sandbox analysis sessions to observe full attack chains and TTPs:

destinationIP:"160.119.69.4".

Malicious IP detected as Remus IOC Malicious IP detected as Remus Stealer

What is Remus Stealer?

Remus Stealer represents the ongoing professionalization of infostealer operations. It is a native 64-bit malware that builds on Lumma's codebase, incorporating advanced evasion techniques while shifting to new infrastructure methods. Key features include browser-focused data theft (especially Chromium-based), session hijacking capabilities that can bypass MFA by stealing active cookies and tokens, and targeting of password managers (e.g., via IndexedDB for 1Password, LastPass, Bitwarden).

It uses custom string obfuscation, direct syscalls, reflective code loading/shellcode injection into browser processes, and blockchain-based C2 resolution via EtherHiding (storing C2 details in Ethereum smart contracts). This makes it resilient and harder to disrupt compared to traditional dead-drop resolvers (e.g., Steam/Telegram used in Lumma). Remus operates in a mature MaaS model with rapid updates, customer support, statistics dashboards, and features emphasizing operational scalability and log management.

ANY.RUN Interactive Sandbox lets analysts investigate Remus Stealer behavior in real time:

View sample detonation

Remus detonated in Interactive Sandbox Remus Stealer detonated in Interactive Sandbox

How Remus Stealer Threatens Businesses and Organizations

Remus poses severe risks by enabling credential theft, session hijacking, and data exfiltration that can lead to:

  • Unauthorized access to corporate accounts, VPNs, cloud services, and internal systems.
  • Financial fraud via stolen crypto wallets or banking credentials.
  • Supply chain and lateral movement opportunities, as stolen sessions/tokens allow attackers to pivot deeper into networks.
  • Data breaches exposing customer information, intellectual property, or compliance-regulated data.
  • Reputational and regulatory damage, including fines from GDPR, CCPA, or similar.

Stolen browser sessions and tokens are particularly dangerous as they often bypass traditional MFA, allowing persistent access without immediate alerts. In corporate environments, this can result in prolonged dwell time for attackers.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most Vulnerable?

Any organization relying on Chromium-based browsers (Chrome, Edge) is vulnerable; however, specific sectors are prime targets:

  • Technology & DevOps: Attackers are actively impersonating open-source tools (Ghidra, dnSpy) to deliver Remus to developers.

  • Finance & Fintech: High-value targets for cryptocurrency wallet theft and banking credential harvesting.

  • Gaming & E-commerce: Targeted for Discord token theft and payment data

Small-to-medium businesses and those with hybrid/remote workforces relying on personal devices or unpatched software are prime targets due to lower security maturity.

Evolution of Remus Stealer

Remus traces back to Lumma Stealer disruptions in late 2025 (doxxing of alleged developers). Transitional "Tenzor" test builds appeared around September 2025, evolving into active Remus campaigns by February 2026. It shifted from Lumma's 32-bit architecture and traditional resolvers to 64-bit with EtherHiding and enhanced anti-analysis (e.g., sandbox DLL checks, PST honeypot detection).

Development under the MaaS model has been rapid: early focus on core theft and delivery reliability, followed by session restoration, proxy support, password manager targeting, and operational tools (worker tracking, duplicate filtering) through March–May 2026.

Notable aspects include campaigns delivering via software search redirection (malvertising for popular tools), with activity rivaling Lumma's. Specific large-scale attacks are often opportunistic via MaaS buyers, but the malware's volume and integration into broader cybercrime ecosystems (initial access brokers) amplify its impact.

Notable Campaign (2026): A massive Traffic Distribution System (TDS) campaign has been identified where fake websites rank high on Google Search for software terms, redirecting users to Remus payloads. The malware is delivered via obfuscated Go loaders that check for virtual machine environments before executing

How Remus Stealer Gets Into Systems and Spreads

Common infection vectors mirror other stealers:

  • Malvertising and search redirection: Fake download pages for software (e.g., converters, utilities) via compromised ads or SEO.
  • Phishing emails with malicious attachments or links.
  • Pirated/cracked software, keygens, and third-party downloaders.
  • Drive-by downloads on compromised sites.
  • Social engineering and fake updates.

It often uses loaders for initial delivery, with good "crypting" (obfuscation) for high callback rates.

How Remus Stealer Function: Sandbox Analysis

View ANY.RUN Sandbox analysis of a Remus Stealer sample

Remus detonated in Interactive Sandbox Remus Stealer detonated in Interactive Sandbox

Remus is a 64-bit infostealer that represents an evolution of Lumma, rather than an entirely new malware family. Since February 2026 campaigns, it has been associated with SEO-poisoning/fake websites mimicking popular open-source tools. It retrieves C2 addresses via EtherHiding instead of conventional resolver chains.

The sample’s functionality after execution depends on the availability of the C2 servers. If they are reachable, the malware typically does the following: it accesses browser data, steals saved passwords, cookies, and cryptocurrency wallets. In some cases, it bypasses Chrome’s Application-Bound Encryption (ABE) through injection into the browser process or a hidden browser desktop. It also performs anti-VM and anti-sandbox checks. If the C2 servers are unavailable, the malware does not reveal itself in any way (except for network connection attempts).

After launch, we can see that the sample generates a large number of network requests and immediately triggers detections related to data theft:

Remus Stealer data exfiltration attempts Remus Stealer data exfiltration attempts

Switching to the Network threats tab, we see traffic characteristic of this malware:

Remus activity in network traffic Remus activity in network traffic

Directly inside the traffic, we can observe all the communication and the name of the C2 domain in this case (the malware has a large number of C2 domains and changes them frequently; samples that are one or two months old usually no longer work due to lack of connection to the server):

Remus network traffic analysis Remus network traffic analysis

Similar data is visible in the HTTP Requests tab:

Remus HTTP requests Remus HTTP requests

Inside the traffic itself, communication with the C2 is visible — for example, the initial submission and receiving success:true as a response:

Remus C2 request & response Remus C2 request & response

Next, we see the malware sending some technical information to the server:

Remus exfiltrating technical data Remus exfiltrating technical data

hwid represents the victim’s Hardware ID, tag is the identifier of the campaign, build, or bot, exp is a Unix Timestamp.

Then we see the sending of a token:

Remus sends a token Remus sends a token

Response: Server response Server response

And the transmission of already encrypted data:

Exfiltration of encrypted data Exfiltration of encrypted data

This type of interaction is observed throughout the entire communication: sending tokens → receiving tokens → sending data.

It is also evident that after registering on the C2 server, the sample transmitted service parameters debug and step, presumably used to track the stages of execution and the state of the malicious process. The values included 2-PRE, 2-EMPTY, step=1, and others, which may indicate the passage of internal data processing stages or preparation for exfiltration.

Additionally, by diving into the data theft detections, we can see which directories and files the stealer attempted to access:

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

How Businesses Can Use ANY.RUN’s Threat Intelligence Feeds and TI Lookup Against Remus Stealer

Threat intelligence can help organizations move from reactive detection to proactive defense.

Threat Intelligence Feeds

Security teams can integrate ANY.RUN Threat Intelligence Feeds into SIEM, EDR, SOAR, XDR, and TIP platforms to automatically detect:

  • Remus-related domains
  • Command-and-control infrastructure
  • Malicious IP addresses
  • Malware hashes
  • Emerging indicators associated with active campaigns

TI Feeds benefits and integration TI Feeds benefits and integration

Because infostealer infrastructure changes rapidly, continuously updated feeds help security teams identify threats before compromise occurs.

ANY.RUN Threat Intelligence Lookup enables analysts and threat hunters to:

  • Search Remus-related IOCs
  • Investigate malware infrastructure
  • Correlate domains, IPs, and hashes
  • Discover emerging indicators linked to active campaigns
  • Conduct retrospective investigations

This accelerates threat hunting and incident response while improving visibility into evolving malware activity.

threatName:"remus".

Remus sandbox analyses in TI Lookup Remus sandbox analyses in TI Lookup

Additional defensive measures:

  • User education on phishing/malvertising; avoid pirated software.
  • Endpoint detection with behavioral monitoring for injection/syscalls.
  • Browser hardening (e.g., limit extensions, use password managers carefully).
  • MFA with phishing-resistant methods; regular credential rotation.
  • Network segmentation, least privilege, and monitoring for anomalous C2 (Ethereum traffic).
  • Patch management and application allowlisting

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Remus Stealer is not just another infostealer; it is a paradigm shift in malware resilience. By weaponizing blockchain for C2 communication and operating a professional MaaS model, it has solved the problem of infrastructure takedown that plagued previous stealers. For defenders, this means shifting from reactive signature-based detection to behavioral analysis—watching for the action of memory injection and browser manipulation rather than the hash of the file.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More
Orcus RAT screenshot
Orcus RAT
orcus rat trojan
Orcus is a modular Remote Access Trojan with some unusual functions. This RAT enables attackers to create plugins using a custom development library and offers a robust core feature set that makes it one of the most dangerous malicious programs in its class.
Read More
Diamotrix screenshot
Diamotrix
diamotrix
Diamotrix is a stealthy cryptocurrency clipper malware that silently monitors the Windows clipboard, waiting for the moment a user copies a digital wallet address. Diamotrix replaces it with an attacker-controlled wallet, invisibly redirecting any resulting transaction. Because blockchain transfers are irreversible, victims rarely discover the theft until the funds are long gone.
Read More
EvilProxy screenshot
EvilProxy
evilproxy
EvilProxy is a phishing-as-a-service (PhaaS) platform that enables cybercriminals to bypass multi-factor authentication (MFA) and hijack user sessions. It leverages reverse proxy techniques to harvest credentials and session cookies, posing a serious threat to both individuals and enterprises.
Read More
Sality screenshot
Sality
sality
Sality is a highly sophisticated malware known for infecting executable files and rapidly spreading across networks. It primarily creates a peer-to-peer botnet that is used for malicious activities such as spamming, data theft, and downloading additional malware. Sality has strong persistence mechanisms, including disabling security software, making it difficult to remove. Its ability to spread quickly and silently, along with its polymorphic nature, allows it to evade detection by traditional antivirus solutions.
Read More