Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
регистрация доменов - на T1583.001 (Domains). Атакующие инвестируют в подготовку инфраструктуры задолго до раздачи пейлоадов
Obfuscation de chaînes identique : encodage unique par chaîne, décodage octet par octet à l’exécution... Obfuscation du flux de contrôle similaire...
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.
Once received and decoded, this access token is used to receive encrypted config data used by Remus to target assets on the victim system. Data collected for logs is then exfiltrated as encrypted POST data.
It will attempt to resolve several domain:port combinations via POST requests... After a connection is established, the stealer sends a POST request to the C2 in order to receive an access token. | Before performing main stealer functionality, Remus will beacon out to its C2 infrastructure. It will attempt to resolve several domain:port combinations via POST requests, and attempt a final connection to find the C2 server using EtherHiding.
Remus tente de résoudre plusieurs combinaisons domaine:port via des requêtes POST
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Инфостилер, распространяемый по модели malware-as-a-service (MaaS); крадет данные из более чем 20 браузеров, множества расширений, криптокошельков, 2FA-инструментов и менеджеров паролей.
Infostealer commercialisé en mode Malware-as-a-Service depuis mars 2026. Il vole notamment des cookies de session/OAuth, intègre Telegram pour la réception des logs, utilise un panneau d’administration, communique avec son C2 via requêtes POST, peut recourir à EtherHiding pour retrouver son C2, récupère une configuration chiffrée après authentification et exfiltre les données collectées sous forme chiffrée.
An information-stealing malware offered as a MaaS platform. It steals victim data, restores Google OAuth cookies, integrates with Telegram for logs, beacons to C2 infrastructure before main execution, retrieves an access token and encrypted configuration, targets assets on the victim system, and exfiltrates collected data via encrypted POST requests.
An information stealer offered as malware-as-a-service that steals data from more than 20 browsers, browser extensions, cryptocurrency wallets, two-factor authentication tools, and password managers. It is believed to be a variant of Lumma Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.