Researchers linked the Remus infostealer to an evolving command-and-control architecture that stores live resolver data in Ethereum smart contracts, extending the malware’s use of EtherHiding beyond earlier Telegram and Steam dead-drop methods. Analysis of contract 0x999941b74F6bbc921D5174A5b29911562cd2D7CF and its 0xc2fb26a6 function exposed a live C2 domain, fightwa[.]biz:5902, which had not appeared in prior public indicators; historical activity showed the infrastructure rotating from a test domain to chalx[.]live:5902 and then to fightwa[.]biz:5902. The domain resolved to 185.53.179.128, an IP already associated with Remus infrastructure, and researchers said monitoring blockchain DomainUpdated events could provide durable visibility into future C2 changes.
Separate infrastructure mapping found the campaign spread across more than 15 ASNs but concentrated at Hostinger International Limited (AS47583) and Team Internet AG (AS206834), with 185.53.179.128 standing out as a likely convergence or exfiltration node. Investigators identified five Ethereum contracts used to hold live C2 data, showing a progression from simple DomainStorage designs to more controlled and stealthier DataStore variants, while malware analysis described Remus as a likely Lumma-derived 64-bit stealer that steals browser credentials, cookies, and cryptocurrency wallets. The malware also inherits Lumma’s browser-memory technique for bypassing Chromium Application-Bound Encryption, while adding compact shellcode, randomized hidden-browser desktop names, anti-analysis checks, and blockchain-backed C2 resilience.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Flashpoint reported that Remus had been offered in underground communities since March 2026 as a Malware-as-a-Service platform with three subscription tiers. The report described this as the malware's commercial emergence in the cybercrime ecosystem.
Researchers reported that Remus uses Lumma-style browser key theft and Chromium Application-Bound Encryption bypass, while adding a compact shellcode payload, randomized hidden-browser desktop names, EtherHiding-based C2 resolution, and anti-analysis checks. They assessed Remus as an evolutionary branch linked to the Lumma ecosystem rather than a direct replacement.
Researchers identified Remus as a new infostealer that emerged in early 2026 and assessed it as a new 64-bit variant closely derived from Lumma Stealer.
Infrastructure analysis found Remus spread across more than 15 ASNs, with concentration at Hostinger International Limited and Team Internet AG, and highlighted 185.53.179.128 as a likely central convergence or exfiltration server. Additional Ethereum pivots uncovered four new smart contracts beyond the previously identified one, bringing the total used to store live C2 information to five.
The Remus campaign registered many .biz domains around the same time in early March through Dynadot, with shared certificate and hosting traits suggesting an automated operation.
By querying Ethereum contract 0x999941b74F6bbc921D5174A5b29911562cd2D7CF through a public RPC endpoint, a researcher identified live C2 domain fightwa[.]biz:5902 that had not appeared in the previously published IoC list. The hosting IP 185.53.179.128 matched infrastructure previously associated with Remus, supporting attribution to the same campaign.
Historical smart-contract activity showed the Remus cluster progressing from a test domain to chalx[.]live:5902 and then to fightwa[.]biz:5902, demonstrating active command-and-control rotation. The latest observed update was anchored as recently as 2026-04-25.
Gen Threat Labs traced Remus infostealer development back to test builds labeled Tenzor in September 2025, indicating the malware's development predates its public identification by several months.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
flashpoint.io
Open sourcecybersecuritynews.com
Open sourceintelinsights.substack.com
Open sourceintelinsights.substack.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.