Remus Stealer is a 64-bit Windows information stealer marketed as a malware-as-a-service offering since March 2026. It has substantial code, configuration, log-structure, administration-panel, and obfuscation similarities to Lumma, and is assessed as a likely derivative or close relative of that malware family. Remus profiles infected hosts and collects browser credentials, web-session cookies, payment information, browsing data, browser-extension data, cryptocurrency-wallet material, two-factor-authentication data, and password-manager data. It also targets Firefox profiles, Roblox cookies, and Steam authentication material, and can capture clipboard contents and screenshots. Remus communicates with command-and-control infrastructure over encrypted HTTP POST traffic, obtains configuration and tasking after host registration, and supports operator-directed file and registry collection, browser-data collection, screenshot capture, arbitrary command execution, and deployment of additional payloads. It uses string and control-flow obfuscation, anti-analysis checks, encrypted configuration and data handling, and an EtherHiding-based command-and-control fallback. Remus has been distributed through impersonated software and game-cheat download sites, search-engine poisoning, traffic-distribution systems, and deceptive repositories and downloads. Campaigns have targeted Windows users, including gamers and security professionals seeking reverse-engineering or developer tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Par ailleurs, les opérateurs ont été observés exploitant la vulnérabilité « CVE-2026-41089 » pour obtenir un accès non autorisé aux systèmes avant d'y installer le malware. | Remus Stealer est un malware de type Infostealer apparu en février 2026. Il appartient à la famille « Lumma Stealer »... Le malware cible notamment les identifiants et mots de passe enregistrés dans les navigateurs Web, les cookies de session, les historiques de navigation, les informations bancaires sauvegardées, les portefeuilles de cryptomonnaies, les jetons d'authentification (tokens)...
40 distinct techniques documented for this family, organized by ATT&CK tactic.
регистрация доменов - на T1583.001 (Domains). Атакующие инвестируют в подготовку инфраструктуры задолго до раздачи пейлоадов
Le malware est fréquemment distribué via des logiciels piratés (cracked software), des faux sites imitant des projets open source, ainsi que des campagnes de malvertising redirigeant les utilisateurs vers des téléchargements malveillants.
The dropper relaunches itself with an encoded Start-Process command through PowerShell -ExecutionPolicy Bypass, creates a screenshot window, and uses Add-MpPreference.
The stealer extensively uses NtCreateFile, NtQueryDirectoryFile, NtReadFile, NtOpenProcess, NtReadVirtualMemory, NtCreateThreadEx, and other native APIs/syscalls.
The first-stage JavaScript dropper is obfuscated using javascript-obfuscator; embedded strings and the loader payload are encoded/encrypted.
Fake GitHub cheat repositories and a GitHub Pages site advertise a Meccha Chameleon cheat but deliver an NSIS installer and infostealer.
Маскировка Match Legitimate Resource Name or Location (T1036.005, Defense Evasion) Имя файла имитирует легитимный установщик проекта
To recover Chromium app-bound encryption keys, Remus opens a browser process, writes a CryptUnprotectMemory stub into allocated RWX memory, and executes it using NtCreateThreadEx.
The dropper executes the loader through rundll32.exe url.dll,FileProtocolHandler; remote DLL tasks are executed by rundll32 with a supplied export name.
Remus reads RobloxCookies.dat, Steam config.vdf and local.vdf, and scans Steam process memory for JWT-like authentication tokens.
Operators can issue tasks to retrieve specified registry values; Remus also enumerates Uninstall keys and queries the Steam InstallPath registry value.
The dropper retrieves the public IP through api.ipify.org, ifconfig.me, ipinfo.io, or icanhazip.com, then uses ipwho.is for geolocation information.
Running processes are enumerated to locate SYSTEM processes with SeImpersonatePrivilege, active browser processes, Steam processes, and to generate Processes.txt.
Remus creates an Info.yml profile containing OS version, elevation, build information, WMI operating-system details, GPU data, usernames, hostnames, display resolution, SMBIOS data, and hardware-derived HWID data.
Matching files are read and packaged; Remus also collects browser databases, Firefox profile files, extension data, Roblox cookies, Steam configuration/token data, software inventory, process lists, and clipboard contents.
The dropper captures a screenshot of the primary monitor for its Telegram installation notification; Remus can optionally capture the desktop using BitBlt.
The dropper posts installation details and a screenshot to Telegram's API; Remus uses WinHTTP HTTP POST requests for C2 registration, profile upload, task polling, and exfiltration.
Маршрутизация Multi-hop Proxy (T1090.003, C2) TDS-цепочка из 4+ промежуточных нод для обфускации
If its three configured C2 domains fail, Remus queries an Ethereum JSON-RPC endpoint and contract to recover a fallback C2 domain.
The JavaScript dropper downloads the loader from a configured payload URL; remote task payloads can also be retrieved through WinHTTP GET.
132 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as an example of malware delivered in a separate SEO poisoning campaign imitating open-source and freeware projects.
Mentioned as an example of malware delivered in a separate SEO poisoning campaign impersonating open-source and freeware projects.
Mentioned as the apparent inspiration for Amatera's redesigned ABE bypass.
A Windows information stealer delivered through fake Meccha Chameleon cheat installers. It uses anti-analysis checks, manually mapped execution through a Go loader, encrypted C2 communications, host profiling, targeted browser/extension theft including Chromium app-bound encryption bypasses, Firefox data collection, Roblox cookies, Steam tokens, clipboard capture, screenshots, and operator-directed file/registry collection. It also supports downloading and executing EXE, DLL, PowerShell, command, and in-memory PE payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.