Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Par ailleurs, les opérateurs ont été observés exploitant la vulnérabilité « CVE-2026-41089 » pour obtenir un accès non autorisé aux systèmes avant d'y installer le malware. | Remus Stealer est un malware de type Infostealer apparu en février 2026. Il appartient à la famille « Lumma Stealer »... Le malware cible notamment les identifiants et mots de passe enregistrés dans les navigateurs Web, les cookies de session, les historiques de navigation, les informations bancaires sauvegardées, les portefeuilles de cryptomonnaies, les jetons d'authentification (tokens)...
23 distinct techniques documented for this family, organized by ATT&CK tactic.
регистрация доменов - на T1583.001 (Domains). Атакующие инвестируют в подготовку инфраструктуры задолго до раздачи пейлоадов
Le malware est fréquemment distribué via des logiciels piratés (cracked software), des faux sites imitant des projets open source, ainsi que des campagnes de malvertising redirigeant les utilisateurs vers des téléchargements malveillants.
Obfuscation de chaînes identique : encodage unique par chaîne, décodage octet par octet à l’exécution... Obfuscation du flux de contrôle similaire...
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.
Once received and decoded, this access token is used to receive encrypted config data used by Remus to target assets on the victim system. Data collected for logs is then exfiltrated as encrypted POST data.
It will attempt to resolve several domain:port combinations via POST requests... After a connection is established, the stealer sends a POST request to the C2 in order to receive an access token. | Before performing main stealer functionality, Remus will beacon out to its C2 infrastructure. It will attempt to resolve several domain:port combinations via POST requests, and attempt a final connection to find the C2 server using EtherHiding.
Remus tente de résoudre plusieurs combinaisons domaine:port via des requêtes POST
Маршрутизация Multi-hop Proxy (T1090.003, C2) TDS-цепочка из 4+ промежуточных нод для обфускации
117 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Инфостилер, распространяемый по модели malware-as-a-service (MaaS); крадет данные из более чем 20 браузеров, множества расширений, криптокошельков, 2FA-инструментов и менеджеров паролей.
Infostealer commercialisé en mode Malware-as-a-Service depuis mars 2026. Il vole notamment des cookies de session/OAuth, intègre Telegram pour la réception des logs, utilise un panneau d’administration, communique avec son C2 via requêtes POST, peut recourir à EtherHiding pour retrouver son C2, récupère une configuration chiffrée après authentification et exfiltre les données collectées sous forme chiffrée.
An information-stealing malware offered as a MaaS platform. It steals victim data, restores Google OAuth cookies, integrates with Telegram for logs, beacons to C2 infrastructure before main execution, retrieves an access token and encrypted configuration, targets assets on the victim system, and exfiltrates collected data via encrypted POST requests.
An information stealer offered as malware-as-a-service that steals data from more than 20 browsers, browser extensions, cryptocurrency wallets, two-factor authentication tools, and password managers. It is believed to be a variant of Lumma Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.