Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Remus Stealer

30
Global rank
15 infographic chevron month
Month rank
14 infographic chevron week
Week rank
0
IOCs

Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

Stealer
Type
Unknown
Origin
1 February, 2026
First seen
16 August, 2026
Last seen

How to analyze Remus Stealer with ANY.RUN

Type
Unknown
Origin
1 February, 2026
First seen
16 August, 2026
Last seen

IOCs

IP addresses
2.16.204.141
48.192.1.65
2.16.164.49
135.232.92.137
20.190.160.128
2.23.246.9
135.232.92.97
48.209.138.168
23.11.41.157
23.59.18.102
172.211.123.250
48.209.138.189
191.252.159.33
172.211.123.248
20.184.175.0
150.171.28.11
192.178.183.101
2.21.110.198
2.16.204.161
23.194.190.132
Hashes
a14c82f0a4088147b6a34d9893f8afeaf0a78b0599486d6d52eea70f89c1e929
14f4d31f632fe6420d911bf9e5d4e72ff9fc01880600f4eee7fd3b0fecc240a5
642a305a6c5c0bd5e1157596e75837bddd3546d89dd78cb68497a3579ef35b00
fc525b684be2945a43ca04de402d74a1ea1901c48bf2eafe5fa814bfccfb4378
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
47e1c4d53c8e724ae33873e22c5caa763366ff3484704dd973929e0da6f95504
06ab381e06178f2a0062db9b1d069adf065c4ff00232426b8d70fa3ad7703a76
93332c49fab1deb87dac6cb5d313900cb20e6e1ba928af128a1d549a44256f68
13cd61b8080a8cc23f42e2d5e599c284868a3985b8e0ddfa65f4f46e083f55c4
bdab963231ad800a8f792e0bbf9a2d5a38294717e0defe280a8cfcf2bf715e3b
ae05ac59eebce8476cb992c22b224035a86f624b6f8c302de97fe8c4549a8bcb
997048c0a0c5394bcda53fdd5e3fd0bde70ce4a5bd666702f1a947d22a82f6ae
6b53eff6a5ac56e0bf7ba156cd1f7116ed637c88de2efa4f72a3922645146044
bca56cfb0caec69e63257f31cb0cb2f0d6b44102b281716682e9526a27a7be4c
be878ba77cca2bb05b23bfc8d966f1804ddfcbb970ee0c4be111876aa020eb83
Domains
slscr.update.microsoft.com
settings-win.data.microsoft.com
www.bing.com
vexdico.shop
login.live.com
ocsp.digicert.com
activation-v2.sls.microsoft.com
client.wns.windows.com
fe3cr.delivery.mp.microsoft.com
crl.microsoft.com
www.microsoft.com
google.com
go.microsoft.com
accounts.google.com
update.googleapis.com
c.bing.com
www.google.com
sb.scorecardresearch.com
edge.microsoft.com
copilot.microsoft.com
URLs
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://github.com:8539/tokens
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://github.com:8811/imports
http://clients2.google.com/time/1/current?cup2key=8:nx8u7sjbyvijmrxv7oiuyaabclkgsfl8bzlkmd9iqle&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
Last Seen at

Recent blog posts

post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 9578
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 4955
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 41071
comments 0

From Lumma’s Ashes: Remus Stealer Uses Blockchain to Steal Your Business Data

Key Takeaways

  • Remus Stealer is a rapidly evolving Malware-as-a-Service infostealer that emerged in 2026.
  • It utilizes EtherHiding, storing C2 addresses in Ethereum smart contracts to avoid takedowns.
  • The malware steals credentials, browser cookies, authentication tokens, and cryptocurrency wallet data.
  • Session theft is one of Remus's most dangerous capabilities because it can bypass MFA by stealing active session cookies directly from browser memory.
  • The malware shows strong technical similarities to Lumma Stealer and may represent its evolutionary successor.
  • Financial services, healthcare, government, technology firms, and MSPs are particularly attractive targets.
  • Common infection vectors include phishing, fake software downloads, malvertising, and fake CAPTCHA campaigns, as well as SEO poisoning and fake GitHub projects to trick tech-savvy users.
  • ANY.RUN's Threat Intelligence Feeds and Threat Intelligence Lookup help defenders proactively identify Remus-related infrastructure, hunt for indicators of compromise, and strengthen detection coverage before attacks escalate.

Pivot from Remus IOCs to sandbox analysis sessions to observe full attack chains and TTPs:

destinationIP:"160.119.69.4".

Malicious IP detected as Remus IOC Malicious IP detected as Remus Stealer

What is Remus Stealer?

Remus Stealer represents the ongoing professionalization of infostealer operations. It is a native 64-bit malware that builds on Lumma's codebase, incorporating advanced evasion techniques while shifting to new infrastructure methods. Key features include browser-focused data theft (especially Chromium-based), session hijacking capabilities that can bypass MFA by stealing active cookies and tokens, and targeting of password managers (e.g., via IndexedDB for 1Password, LastPass, Bitwarden).

It uses custom string obfuscation, direct syscalls, reflective code loading/shellcode injection into browser processes, and blockchain-based C2 resolution via EtherHiding (storing C2 details in Ethereum smart contracts). This makes it resilient and harder to disrupt compared to traditional dead-drop resolvers (e.g., Steam/Telegram used in Lumma). Remus operates in a mature MaaS model with rapid updates, customer support, statistics dashboards, and features emphasizing operational scalability and log management.

ANY.RUN Interactive Sandbox lets analysts investigate Remus Stealer behavior in real time:

View sample detonation

Remus detonated in Interactive Sandbox Remus Stealer detonated in Interactive Sandbox

How Remus Stealer Threatens Businesses and Organizations

Remus poses severe risks by enabling credential theft, session hijacking, and data exfiltration that can lead to:

  • Unauthorized access to corporate accounts, VPNs, cloud services, and internal systems.
  • Financial fraud via stolen crypto wallets or banking credentials.
  • Supply chain and lateral movement opportunities, as stolen sessions/tokens allow attackers to pivot deeper into networks.
  • Data breaches exposing customer information, intellectual property, or compliance-regulated data.
  • Reputational and regulatory damage, including fines from GDPR, CCPA, or similar.

Stolen browser sessions and tokens are particularly dangerous as they often bypass traditional MFA, allowing persistent access without immediate alerts. In corporate environments, this can result in prolonged dwell time for attackers.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Victimology: Who Is Most Vulnerable?

Any organization relying on Chromium-based browsers (Chrome, Edge) is vulnerable; however, specific sectors are prime targets:

  • Technology & DevOps: Attackers are actively impersonating open-source tools (Ghidra, dnSpy) to deliver Remus to developers.

  • Finance & Fintech: High-value targets for cryptocurrency wallet theft and banking credential harvesting.

  • Gaming & E-commerce: Targeted for Discord token theft and payment data

Small-to-medium businesses and those with hybrid/remote workforces relying on personal devices or unpatched software are prime targets due to lower security maturity.

Evolution of Remus Stealer

Remus traces back to Lumma Stealer disruptions in late 2025 (doxxing of alleged developers). Transitional "Tenzor" test builds appeared around September 2025, evolving into active Remus campaigns by February 2026. It shifted from Lumma's 32-bit architecture and traditional resolvers to 64-bit with EtherHiding and enhanced anti-analysis (e.g., sandbox DLL checks, PST honeypot detection).

Development under the MaaS model has been rapid: early focus on core theft and delivery reliability, followed by session restoration, proxy support, password manager targeting, and operational tools (worker tracking, duplicate filtering) through March–May 2026.

Notable aspects include campaigns delivering via software search redirection (malvertising for popular tools), with activity rivaling Lumma's. Specific large-scale attacks are often opportunistic via MaaS buyers, but the malware's volume and integration into broader cybercrime ecosystems (initial access brokers) amplify its impact.

Notable Campaign (2026): A massive Traffic Distribution System (TDS) campaign has been identified where fake websites rank high on Google Search for software terms, redirecting users to Remus payloads. The malware is delivered via obfuscated Go loaders that check for virtual machine environments before executing

How Remus Stealer Gets Into Systems and Spreads

Common infection vectors mirror other stealers:

  • Malvertising and search redirection: Fake download pages for software (e.g., converters, utilities) via compromised ads or SEO.
  • Phishing emails with malicious attachments or links.
  • Pirated/cracked software, keygens, and third-party downloaders.
  • Drive-by downloads on compromised sites.
  • Social engineering and fake updates.

It often uses loaders for initial delivery, with good "crypting" (obfuscation) for high callback rates.

How Remus Stealer Function: Sandbox Analysis

View ANY.RUN Sandbox analysis of a Remus Stealer sample

Remus detonated in Interactive Sandbox Remus Stealer detonated in Interactive Sandbox

Remus is a 64-bit infostealer that represents an evolution of Lumma, rather than an entirely new malware family. Since February 2026 campaigns, it has been associated with SEO-poisoning/fake websites mimicking popular open-source tools. It retrieves C2 addresses via EtherHiding instead of conventional resolver chains.

The sample’s functionality after execution depends on the availability of the C2 servers. If they are reachable, the malware typically does the following: it accesses browser data, steals saved passwords, cookies, and cryptocurrency wallets. In some cases, it bypasses Chrome’s Application-Bound Encryption (ABE) through injection into the browser process or a hidden browser desktop. It also performs anti-VM and anti-sandbox checks. If the C2 servers are unavailable, the malware does not reveal itself in any way (except for network connection attempts).

After launch, we can see that the sample generates a large number of network requests and immediately triggers detections related to data theft:

Remus Stealer data exfiltration attempts Remus Stealer data exfiltration attempts

Switching to the Network threats tab, we see traffic characteristic of this malware:

Remus activity in network traffic Remus activity in network traffic

Directly inside the traffic, we can observe all the communication and the name of the C2 domain in this case (the malware has a large number of C2 domains and changes them frequently; samples that are one or two months old usually no longer work due to lack of connection to the server):

Remus network traffic analysis Remus network traffic analysis

Similar data is visible in the HTTP Requests tab:

Remus HTTP requests Remus HTTP requests

Inside the traffic itself, communication with the C2 is visible — for example, the initial submission and receiving success:true as a response:

Remus C2 request & response Remus C2 request & response

Next, we see the malware sending some technical information to the server:

Remus exfiltrating technical data Remus exfiltrating technical data

hwid represents the victim’s Hardware ID, tag is the identifier of the campaign, build, or bot, exp is a Unix Timestamp.

Then we see the sending of a token:

Remus sends a token Remus sends a token

Response: Server response Server response

And the transmission of already encrypted data:

Exfiltration of encrypted data Exfiltration of encrypted data

This type of interaction is observed throughout the entire communication: sending tokens → receiving tokens → sending data.

It is also evident that after registering on the C2 server, the sample transmitted service parameters debug and step, presumably used to track the stages of execution and the state of the malicious process. The values included 2-PRE, 2-EMPTY, step=1, and others, which may indicate the passage of internal data processing stages or preparation for exfiltration.

Additionally, by diving into the data theft detections, we can see which directories and files the stealer attempted to access:

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

Remus reaching system and app directories for data exfiltration Remus reaching system and app directories for data exfiltration

How Businesses Can Use ANY.RUN’s Threat Intelligence Feeds and TI Lookup Against Remus Stealer

Threat intelligence can help organizations move from reactive detection to proactive defense.

Threat Intelligence Feeds

Security teams can integrate ANY.RUN Threat Intelligence Feeds into SIEM, EDR, SOAR, XDR, and TIP platforms to automatically detect:

  • Remus-related domains
  • Command-and-control infrastructure
  • Malicious IP addresses
  • Malware hashes
  • Emerging indicators associated with active campaigns

TI Feeds benefits and integration TI Feeds benefits and integration

Because infostealer infrastructure changes rapidly, continuously updated feeds help security teams identify threats before compromise occurs.

ANY.RUN Threat Intelligence Lookup enables analysts and threat hunters to:

  • Search Remus-related IOCs
  • Investigate malware infrastructure
  • Correlate domains, IPs, and hashes
  • Discover emerging indicators linked to active campaigns
  • Conduct retrospective investigations

This accelerates threat hunting and incident response while improving visibility into evolving malware activity.

threatName:"remus".

Remus sandbox analyses in TI Lookup Remus sandbox analyses in TI Lookup

Additional defensive measures:

  • User education on phishing/malvertising; avoid pirated software.
  • Endpoint detection with behavioral monitoring for injection/syscalls.
  • Browser hardening (e.g., limit extensions, use password managers carefully).
  • MFA with phishing-resistant methods; regular credential rotation.
  • Network segmentation, least privilege, and monitoring for anomalous C2 (Ethereum traffic).
  • Patch management and application allowlisting

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Remus Stealer is not just another infostealer; it is a paradigm shift in malware resilience. By weaponizing blockchain for C2 communication and operating a professional MaaS model, it has solved the problem of infrastructure takedown that plagued previous stealers. For defenders, this means shifting from reactive signature-based detection to behavioral analysis—watching for the action of memory injection and browser manipulation rather than the hash of the file.

Trial TI Lookup to start gathering actionable threat intelligence on the malware that threatens your business sector and region: just sign up to ANY.RUN.

HAVE A LOOK AT

Fog Ransomware screenshot
Fog is a ransomware strain that locks and steals sensitive information both on Windows and Linux endpoints. The medial ransom demand is $220,000. The medial payment is $100,000. First spotted in the spring of 2024, it was used to attack educational organizations in the USA, later expanding on other sectors and countries. Main distribution method — compromised VPN credentials.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
Meduza Stealer screenshot
Meduza Stealer is an information-stealing malware primarily targeting Windows systems, designed to harvest sensitive data such as login credentials, browsing histories, cookies, cryptocurrency wallets, and password manager data. It has advanced anti-detection mechanisms, allowing it to evade many antivirus programs. The malware is distributed through various means, including phishing emails and malicious links. It’s marketed on underground forums and Telegram channels.
Read More
Agent Tesla screenshot
Agent Tesla
agenttesla trojan rat stealer
Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More
Phorpiex screenshot
Phorpiex
phorpiex
Phorpiex is a malicious software that has been a significant threat in the cybersecurity landscape since 2016. It is a modular malware known for its ability to maintain an extensive botnet. Unlike other botnets, Phorpiex does not concentrate on DDoS attacks. Instead, it has been involved in numerous large-scale spam email campaigns and the distribution of other malicious payloads, such as LockBit.
Read More