Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Remus Stealer

23
Global rank
21 infographic chevron month
Month rank
32 infographic chevron week
Week rank

Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

Stealer
Type
Unknown
Origin
1 February, 2026
First seen
25 September, 2026
Last seen

How to analyze Remus Stealer with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
25 September, 2026
Last seen

IOCs

IP addresses
192.178.183.102
150.171.22.17
135.233.95.135
150.171.27.10
23.194.190.151
142.251.20.132
2.21.110.208
142.251.20.113
142.251.20.95
192.178.183.139
15.204.253.8
18.244.18.27
2.21.110.200
184.25.51.9
150.171.109.101
150.171.28.10
2.21.239.138
150.171.74.13
20.190.159.73
192.178.183.113
Hashes
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
3377a873db531113d79919e7a89369a79a602bac6ae09b9864b9378dc285f345
a3eb276fbd19dce2b00db6937578b214b9e33d67487659fe0bf21a86225ece73
a41670d52423ba69c7a65e7e153e7b9994e8dd0370c584bda0714bd61c49c578
54241ebe651a8344235cc47afd274c080abaebc8c3a25afb95d8373b6a5670a2
bbd37d41b7de6f93948fa2437a7699d4c30a3c39e736179702f212cb36a3133c
35872a3343d4b4768fe4702a8dc18b749933e81210db13466ad172bd2880f6eb
de6d7b7c2427ec4e738407d7834b71941f69166b030355e00f325ff1391df5a1
cf26310b073b0891996ecd761c6cb53f00193dee524213a9fb34225d636ec4b7
Domains
browser.events.data.msn.com
edge.microsoft.com
update.googleapis.com
api.msn.com
accounts.google.com
www.google.com
sb.scorecardresearch.com
play.google.com
r.bing.com
settings-win.data.microsoft.com
c.msn.com
r.msftstatic.com
c.bing.com
srtb.msn.com
clientservices.googleapis.com
config.edge.skype.com
safebrowsingohttpgateway.googleapis.com
services.bingapis.com
clients2.googleusercontent.com
ogads-pa.clients6.google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/microsoft%20secure%20server%20ca%202026.crl
http://github.com:8239/profiles
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://clients2.google.com/time/1/current?cup2key=8:ytckquyds-khjvjhny5twnx6m5kfdfdcbxc2-aqthdg&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://www.google.com/async/newtab_ogb?hl=en-us&async=fixed:0
https://www.google.com/async/ddljson?async=ntp:2
https://www.google.com/async/newtab_promos
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://www.gstatic.com/og/_/ss/k=og.qtm.slf9k6xbtbq.l.w.o/m=qmd,qcwid,d_b_gm3,d_wi_gm3,d_lo_gm3/excm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/ct=zgms/rs=aa2yrtvwgogfe9gndtczfn4pb5nwdekvla
https://www.gstatic.com/images/branding/googlelogo/svg/googlelogo_surface_dark_74x24px.svg
https://www.gstatic.com/og/_/js/k=og.qtm.en_us.5trdsu38me0.2019.o/rt=j/m=q_dnp,qmd,qcwid,qapid,qald,qads/exm=qaaw,qabr,qadd,qaid,qalo,qebr,qein,qhaw,qhawgm3,qhba,qhbr,qhbrgm3,qhch,qhchgm3,qhga,qhid,qhidgm3,qhin,qhlo,qhlogm3,qhmn,qhpc,qhsf,qhsfgm3,qhtt/d=1/ed=1/rs=aa2yrts0aimt3hmbpqqlii-xsgvijh3lkw
https://ogads-pa.clients6.google.com/$rpc/google.internal.onegoogle.asyncdata.v1.asyncdataservice/getasyncdata
https://play.google.com/log?format=json&hasfast=true
https://update.googleapis.com/service/update2/json?cup2key=14:esvmdsi67zlgviuyl4shyvmlmh17w0snvq4fj5susy4&cup2hreq=1b86786c5088d2221b3738ce7c26c0a7650c9b945fc8e182b2a300b13aed49f2
http://clients2.google.com/time/1/current?cup2key=8:ogni4epogry7bl5i-zs8f5vtjwbo_-ddn0qv7dp61rc&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
Last Seen at
Last Seen at

Recent blog posts

post image
ANY.RUN at RootedCON Valencia 2026: Where Cyb...
watchers 769
comments 0
post image
Phishing Risk Across 5 Key US Industries: ANY...
watchers 5619
comments 0
post image
CSuite Targets US and EU Organizations with D...
watchers 11500
comments 0

From Lumma’s Ashes: Remus Stealer Uses Blockchain to Steal Your Business Data

Key Takeaways

  • Remus Stealer is a rapidly evolving Malware-as-a-Service infostealer that emerged in 2026.
  • It utilizes EtherHiding, storing C2 addresses in Ethereum smart contracts to avoid takedowns.
  • The malware steals credentials, browser cookies, authentication tokens, and cryptocurrency wallet data.
  • Session theft is one of Remus's most dangerous capabilities because it can bypass MFA by stealing active session cookies directly from browser memory.
  • The malware shows strong technical similarities to Lumma Stealer and may represent its evolutionary successor.
  • Financial services, healthcare, government, technology firms, and MSPs are particularly attractive targets.
  • Common infection vectors include phishing, fake software downloads, malvertising, and fake CAPTCHA campaigns, as well as SEO poisoning and fake GitHub projects to trick tech-savvy users.
  • ANY.RUN's Threat Intelligence Feeds and Threat Intelligence Lookup help defenders proactively identify Remus-related infrastructure, hunt for indicators of compromise, and strengthen detection coverage before attacks escalate.

Pivot from Remus IOCs to sandbox analysis sessions to observe full attack chains and TTPs:

destinationIP:"160.119.69.4".

Malicious IP detected as Remus IOC Malicious IP detected as Remus Stealer

What is Remus Stealer?

Remus Stealer represents the ongoing professionalization of infostealer operations. It is a native 64-bit malware that builds on Lumma's codebase, incorporating advanced evasion techniques while shifting to new infrastructure methods. Key features include browser-focused data theft (especially Chromium-based), session hijacking capabilities that can bypass MFA by stealing active cookies and tokens, and targeting of password managers (e.g., via IndexedDB for 1Password, LastPass, Bitwarden).

It uses custom string obfuscation, direct syscalls, reflective code loading/shellcode injection into browser processes, and blockchain-based C2 resolution via EtherHiding (storing C2 details in Ethereum smart contracts). This makes it resilient and harder to disrupt compared to traditional dead-drop resolvers (e.g., Steam/Telegram used in Lumma). Remus operates in a mature MaaS model with rapid updates, customer support, statistics dashboards, and features emphasizing operational scalability and log management.

ANY.RUN Interactive Sandbox lets analysts investigate Remus Stealer behavior in real time:

View sample detonation

Remus detonated in Interactive Sandbox Remus Stealer detonated in Interactive Sandbox

How Remus Stealer Threatens Businesses and Organizations

Remus poses severe risks by enabling credential theft, session hijacking, and data exfiltration that can lead to:

  • Unauthorized access to corporate accounts, VPNs, cloud services, and internal systems.
  • Financial fraud via stolen crypto wallets or banking credentials.
  • Supply chain and lateral movement opportunities, as stolen sessions/tokens allow attackers to pivot deeper into networks.
  • Data breaches exposing customer information, intellectual property, or compliance-regulated data.
  • Reputational and regulatory damage, including fines from GDPR, CCPA, or similar.

Stolen browser sessions and tokens are particularly dangerous as they often bypass traditional MFA, allowing persistent access without immediate alerts. In corporate environments, this can result in prolonged dwell time for attackers.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most Vulnerable?

Any organization relying on Chromium-based browsers (Chrome, Edge) is vulnerable; however, specific sectors are prime targets:

  • Technology & DevOps: Attackers are actively impersonating open-source tools (Ghidra, dnSpy) to deliver Remus to developers.

  • Finance & Fintech: High-value targets for cryptocurrency wallet theft and banking credential harvesting.

  • Gaming & E-commerce: Targeted for Discord token theft and payment data

Small-to-medium businesses and those with hybrid/remote workforces relying on personal devices or unpatched software are prime targets due to lower security maturity.

Evolution of Remus Stealer

Remus traces back to Lumma Stealer disruptions in late 2025 (doxxing of alleged developers). Transitional "Tenzor" test builds appeared around September 2025, evolving into active Remus campaigns by February 2026. It shifted from Lumma's 32-bit architecture and traditional resolvers to 64-bit with EtherHiding and enhanced anti-analysis (e.g., sandbox DLL checks, PST honeypot detection).

Development under the MaaS model has been rapid: early focus on core theft and delivery reliability, followed by session restoration, proxy support, password manager targeting, and operational tools (worker tracking, duplicate filtering) through March–May 2026.

Notable aspects include campaigns delivering via software search redirection (malvertising for popular tools), with activity rivaling Lumma's. Specific large-scale attacks are often opportunistic via MaaS buyers, but the malware's volume and integration into broader cybercrime ecosystems (initial access brokers) amplify its impact.

Notable Campaign (2026): A massive Traffic Distribution System (TDS) campaign has been identified where fake websites rank high on Google Search for software terms, redirecting users to Remus payloads. The malware is delivered via obfuscated Go loaders that check for virtual machine environments before executing

How Remus Stealer Gets Into Systems and Spreads

Common infection vectors mirror other stealers:

  • Malvertising and search redirection: Fake download pages for software (e.g., converters, utilities) via compromised ads or SEO.
  • Phishing emails with malicious attachments or links.
  • Pirated/cracked software, keygens, and third-party downloaders.
  • Drive-by downloads on compromised sites.
  • Social engineering and fake updates.

It often uses loaders for initial delivery, with good "crypting" (obfuscation) for high callback rates.

How Remus Stealer Function: Sandbox Analysis

View ANY.RUN Sandbox analysis of a Remus Stealer sample

Remus detonated in Interactive Sandbox Remus Stealer detonated in Interactive Sandbox

Remus is a 64-bit infostealer that represents an evolution of Lumma, rather than an entirely new malware family. Since February 2026 campaigns, it has been associated with SEO-poisoning/fake websites mimicking popular open-source tools. It retrieves C2 addresses via EtherHiding instead of conventional resolver chains.

The sample’s functionality after execution depends on the availability of the C2 servers. If they are reachable, the malware typically does the following: it accesses browser data, steals saved passwords, cookies, and cryptocurrency wallets. In some cases, it bypasses Chrome’s Application-Bound Encryption (ABE) through injection into the browser process or a hidden browser desktop. It also performs anti-VM and anti-sandbox checks. If the C2 servers are unavailable, the malware does not reveal itself in any way (except for network connection attempts).

After launch, we can see that the sample generates a large number of network requests and immediately triggers detections related to data theft:

Remus Stealer data exfiltration attempts Remus Stealer data exfiltration attempts

Switching to the Network threats tab, we see traffic characteristic of this malware:

Remus activity in network traffic Remus activity in network traffic

Directly inside the traffic, we can observe all the communication and the name of the C2 domain in this case (the malware has a large number of C2 domains and changes them frequently; samples that are one or two months old usually no longer work due to lack of connection to the server):

Remus network traffic analysis Remus network traffic analysis

Similar data is visible in the HTTP Requests tab:

Remus HTTP requests Remus HTTP requests

Inside the traffic itself, communication with the C2 is visible — for example, the initial submission and receiving success:true as a response:

Remus C2 request & response Remus C2 request & response

Next, we see the malware sending some technical information to the server:

Remus exfiltrating technical data Remus exfiltrating technical data

hwid represents the victim’s Hardware ID, tag is the identifier of the campaign, build, or bot, exp is a Unix Timestamp.

Then we see the sending of a token:

Remus sends a token Remus sends a token

Response: Server response Server response

And the transmission of already encrypted data:

Exfiltration of encrypted data Exfiltration of encrypted data

This type of interaction is observed throughout the entire communication: sending tokens → receiving tokens → sending data.

It is also evident that after registering on the C2 server, the sample transmitted service parameters debug and step, presumably used to track the stages of execution and the state of the malicious process. The values included 2-PRE, 2-EMPTY, step=1, and others, which may indicate the passage of internal data processing stages or preparation for exfiltration.

Additionally, by diving into the data theft detections, we can see which directories and files the stealer attempted to access:

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

How Businesses Can Use ANY.RUN’s Threat Intelligence Feeds and TI Lookup Against Remus Stealer

Threat intelligence can help organizations move from reactive detection to proactive defense.

Threat Intelligence Feeds

Security teams can integrate ANY.RUN Threat Intelligence Feeds into SIEM, EDR, SOAR, XDR, and TIP platforms to automatically detect:

  • Remus-related domains
  • Command-and-control infrastructure
  • Malicious IP addresses
  • Malware hashes
  • Emerging indicators associated with active campaigns

TI Feeds benefits and integration TI Feeds benefits and integration

Because infostealer infrastructure changes rapidly, continuously updated feeds help security teams identify threats before compromise occurs.

ANY.RUN Threat Intelligence Lookup enables analysts and threat hunters to:

  • Search Remus-related IOCs
  • Investigate malware infrastructure
  • Correlate domains, IPs, and hashes
  • Discover emerging indicators linked to active campaigns
  • Conduct retrospective investigations

This accelerates threat hunting and incident response while improving visibility into evolving malware activity.

threatName:"remus".

Remus sandbox analyses in TI Lookup Remus sandbox analyses in TI Lookup

Additional defensive measures:

  • User education on phishing/malvertising; avoid pirated software.
  • Endpoint detection with behavioral monitoring for injection/syscalls.
  • Browser hardening (e.g., limit extensions, use password managers carefully).
  • MFA with phishing-resistant methods; regular credential rotation.
  • Network segmentation, least privilege, and monitoring for anomalous C2 (Ethereum traffic).
  • Patch management and application allowlisting

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Remus Stealer is not just another infostealer; it is a paradigm shift in malware resilience. By weaponizing blockchain for C2 communication and operating a professional MaaS model, it has solved the problem of infrastructure takedown that plagued previous stealers. For defenders, this means shifting from reactive signature-based detection to behavioral analysis—watching for the action of memory injection and browser manipulation rather than the hash of the file.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
BlackMatter screenshot
BlackMatter
blackmatter
BlackMatter is a ransomware strain operating as a Ransomware-as-a-Service (RaaS), designed to encrypt files, remove recovery options, and extort victims across critical industries. Emerging in 2021, it quickly became a major concern due to its ability to evade defenses, spread across networks, and cause large-scale operational disruption, forcing security teams to act against a highly destructive and persistent threat.
Read More
Emmenhtal screenshot
Emmenhtal
emmenhtal
First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.
Read More
Tycoon 2FA screenshot
Tycoon 2FA
tycoon
Tycoon 2FA is a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) protections, particularly targeting Microsoft 365 and Gmail accounts. Its advanced evasion techniques and modular architecture make it a significant threat to organizations relying on MFA for security.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More
Spyware screenshot
Spyware
spyware
Spyware is a stealth form of malware whose primary objective is to gather sensitive information, such as personal data, login credentials, and financial details, by monitoring user activities and exploiting system vulnerabilities. Spyware operates secretly in the background, evading detection while transmitting collected data to cybercriminals, who can then use it for malicious purposes like identity theft, financial fraud, or espionage.
Read More