Remus is a Windows information stealer distributed through SEO-poisoned websites impersonating cracked software and pirated games, with campaigns using Turkish-language lures. It has also been deployed through ClickFix social-engineering chains in which victims are induced to execute malicious PowerShell commands, including campaigns using the ErrTraffic delivery service and Cruciferra loader. Remus injects into Chromium-based browser processes to obtain browser vault data and collects saved credentials, session cookies, browsing data, cryptographic-wallet extension data, password-manager data, gaming-platform artifacts, FTP credentials, clipboard contents, screenshots, enterprise email storage, and host information. It targets locally stored artifacts from Claude, Cursor, and OpenCode, which can include authentication tokens, configuration data, and development context. Remus resolves active command-and-control infrastructure through an Ethereum smart contract, facilitating backend rotation, and exfiltrates collected information over HTTP POST while disguising traffic with spoofed request headers. It can retrieve browser encryption material and enable offline decryption of stolen browser secrets. The malware is commonly delivered through shared fake-software distribution infrastructure alongside other infostealer families.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The loader then uses process hollowing to place the Remus stealer inside ServiceModelReg.exe.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
The campaign ... begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript ... retrieving JavaScript for deceptive lures such as fake Google reCAPTCHA, Cloudflare Turnstile, or a Blue Screen of Death. Victims are then prompted to copy and execute a malicious PowerShell command.
This report summarizes the distribution channels, number of Infostealers, number of detections, and target companies that were disguised as Infostealers collected during the month of July 2026.
Once a victim extracts the fake archive and runs the bundled executable, Remus injects into running Chromium-based browsers using remote threads.
“Like a session token, a valid JWT may grant direct account access... [and] bypasses regular authentication using a username and password and also bypasses MFA challenges.”
“Session tokens and API keys are sought specifically by threat actors because it is often possible to replay those secrets and bypass credential-based authentication.”
Some agents keep access tokens or refresh tokens locally... MCP configurations... may hold endpoints, headers, environment variables, API keys, or other authentication details for external tools.
Criminals are adapting established stealers to collect valuable files stored in predictable local folders... a local agent directory can contain far more than settings... authentication files, conversation databases, recent-project data, and connected-service settings.
The malware also forges the HTTP Host header to mimic a major technology vendor, which helps outbound traffic blend in with normal telemetry and reduces the chance that simple filtering rules will catch it.
That URL then becomes the destination for the stolen data, pushed via HTTP POST requests that disguise the payload as diagnostic or telemetry logs.
276 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Infostealer responsible for the analyzed credential dump from 5,871 infected machines. The dataset contained credentials, browser/session tokens, API keys, JWTs, and JWEs that could enable account takeover and abuse of AI-service accounts and API credits.
Information stealer adapted to collect local artifacts from Claude, Cursor, and OpenCode, potentially including tokens, project data, configurations, and prompt histories.
Information stealer observed targeting locally stored data from the Claude, Cursor, and OpenCode AI coding agents.
Information-stealing malware identified in an infected Windows 11 host after the user downloaded a trojanized game; the associated log contained OpenAI and ChatGPT session data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.