REMUS is a 64-bit information-stealing malware family assessed as an evolutionary branch of Lumma Stealer that emerged in early 2026 and rapidly developed into a malware-as-a-service offering. It is designed to harvest browser credentials, cookies, cryptocurrency-related data, clipboard contents, screenshots, and other host information, with later development emphasizing theft of authenticated session artifacts and restore tokens to enable persistent account compromise rather than simple password theft. Reported targeting has included browser data stores, password-manager-related artifacts such as IndexedDB content associated with browser extensions, and consumer platforms including Discord, Steam, Riot Games, and Telegram.
Technically, REMUS shares multiple distinctive traits with Lumma, including similar string obfuscation, anti-virtualization checks, direct syscall usage, control-flow obfuscation, and a notable Chromium Application-Bound Encryption bypass. It can recover the browser master key by interacting with a live browser process and decrypting protected key material from memory, allowing theft of protected browser secrets. If direct interaction with an existing browser process fails, it can launch a hidden browser instance on a separate desktop to continue collection. REMUS also incorporates anti-analysis checks for sandbox and research environments and has been observed using blockchain-based dead-drop resolution through EtherHiding to retrieve command-and-control information dynamically.
The malware has been distributed through several criminal delivery ecosystems, including ClickFix social-engineering chains that trick users into executing malicious commands, SEO-poisoned crack and keygen lures, compromised WordPress-based traffic distribution systems, and loaders such as GoFlateLoader and SmokeLoader. It has also appeared alongside other commodity stealers in broad malware distribution campaigns. Underground marketing and observed development indicate a commercialized operation with subscription-style access, operator support, delivery workflows, statistics, and affiliate-oriented management features. REMUS is associated with financially motivated cybercrime and reflects the broader industrialization of the infostealer ecosystem, where stolen credentials, cookies, and session material are monetized through account takeover, fraud, resale, and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
OLE32.dll functions (CoCreateInstance, CoInitialize, CoSetProxyBlanket) indicate WMI-based system profiling through COM interfaces.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
Obfuscation and encryption for the injected ErrTraffic script (using AES and JavaScript obfuscation).
Observations indicate that such campaigns make use of fake interfaces impersonating Google reCAPTCHA and Cloudflare verification pages, as well as deceptive pages associated with Google Meet, QR code services and other well-known platforms.
Rather than reading the key off disk, Remus injects a small shellcode into the live browser process to locate and decrypt the master key from inside the browser’s own memory.
SockS5 proxy integration, antivirtualization controls, gaming-platform targeting, as well as deeper password harvesting were all added to the malware.
This initial effort focused on harvesting saved credentials... but later expanded into hijacking sessions... REMUS consistently promoted browser cookies, authentication tokens, workflows to restore sessions, and proxy-assisted continuity mechanisms as central operational features.
The final payloads GoFlateLoader delivers are all information stealers, programs designed to quietly harvest saved passwords, browser data, and cryptocurrency wallet credentials from infected machines.
Initially focused on browser credential theft and basic log management
This objective was further reinforced by repeated targeting of Discord, Steam, Riot Games, and Telegram environments... As of April 2026, the operator has implemented collection capabilities associated with Bitwarden, 1Password, LastPass, and IndexedDB-based browser storage mechanisms commonly used to retain locally authenticated data...
It scans for DLLs linked to known analysis platforms and checks for a specific honeypot file on disk.
April marked another strategic transition in REMUS's evolution, this time toward authentication-based session persistence and browser-side artifact collection... It also included IndexedDB extractions linked to browser extensions associated with the 1Password and LastPass browser extensions...
A type of advanced remote access Trojan called an infostealer operates silently within infected systems, gathering cookies, authentication tokens, stored passwords, fingerprints, and other telemetry from the infected system before packaging the information into standardized 'stealer logs' for exfiltration.
Started as a single Ethereum contract which expanded into a cluster of 5 contracts, multiple operator wallets... The development started with the basic DomainStorage with no validation moved to the hardened DataStore variants.
I was able to retrieve the live C2 domain... deploying on ports 61611 & 61617, along with 2 additional live C2 domains.
The plugin communicates with baxe[.]pics on port 48261 over unencrypted HTTP... The C2 expects file uploads via POST requests, returning structured JSON responses that indicate a Node.js/Express backend.
SockS5 proxy integration... was added to the malware... There were repeated references throughout the campaign to 'Restore' capabilities, multi-proxy compatibility, and token recovery workflows...
ErrTraffic v3, documented by LevelBlue in April 2026, uses the EtherHiding technique as DDR. The injected script on compromised WordPress sites queries a smart contract on a blockchain to retrieve the ErrTraffic C2 server.
In some cases, malicious components may establish persistence on the system, attempt to weaken the operation of security software and enable the download of additional malicious files.
Remus introduces a key upgrade in how it contacts its command-and-control servers... Remus replaces this with EtherHiding, embedding the server address inside an Ethereum blockchain smart contract... Remus queries the smart contract at runtime over a public endpoint and pulls the current server address.
232 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family distributed through ClickFix attack chains, associated in the content with credential and sensitive-data theft.
An infostealer distributed in June 2026, observed in campaigns masquerading as illegal software such as cracks and keygens and delivered via file-sharing/cloud storage sites.
Malware family distributed through fake verification pages in the ClickFix campaign.
Stealer payload delivered in the ClickFix campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.