The Remus Windows infostealer is being distributed through SEO-poisoned fake cracked-software and warez sites, with repeated Turkish-language lures indicating a likely focus on Turkish-speaking users seeking pirated tools and games. After execution, the malware injects into active Chromium-based browser processes to access browser vault data and steal saved passwords, cookies, crypto wallet information, password manager contents, FTP credentials, clipboard data, screenshots, enterprise email storage files, gaming platform data, and system reconnaissance details.
Researchers reported that Remus resolves its command-and-control infrastructure through an Ethereum smart contract, allowing operators to rotate backend servers without updating the malware binary. Stolen data is then exfiltrated over HTTP POST to newly registered domains, in some cases with a spoofed Host header designed to resemble legitimate technology vendor telemetry traffic. The campaign appears to rely on rotating domains and IPs and to share open-directory delivery infrastructure with other infostealer families, highlighting a broader fake-cracked-software distribution ecosystem rather than a single isolated malware operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-30, Unit 42 published findings on an active Remus infostealer campaign spread through SEO-poisoned fake cracked-software sites using Turkish-language lures. The report detailed browser injection, credential theft, Ethereum smart-contract-based C2 resolution, and shared multi-family delivery infrastructure.
Unit 42 reported that several open-directory malware delivery domains hosting Remus and other infostealers had fresh samples uploaded as recently as 2026-07-27, indicating the distribution infrastructure was actively maintained.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceraw.githubusercontent.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.