Gen Threat Labs identified Remus as a 64-bit information stealer and evolutionary continuation of Lumma Stealer, first observed in campaigns around January–February 2026. The malware retains Lumma-like string obfuscation, anti-VM checks, direct syscalls, indirect control-flow obfuscation, and browser-data theft, while using a browser-process shellcode injection technique to recover Chrome’s v20_master_key and bypass Application-Bound Encryption. It also steals credentials, cookies, cryptocurrency-related data, clipboard contents, and Outlook PST data, while adding sandbox-DLL checks and a honey PST-file anti-analysis mechanism.
Remus replaced Lumma’s Steam and Telegram dead-drop C2 resolution with EtherHiding, using Ethereum smart contracts to resolve command-and-control infrastructure at runtime. Its operator said the malware has been sold as a malware-as-a-service offering since February 2026, with roughly 200 active customers, and acknowledged reworking code from transitional Tensor/Tenzor builds linked by researchers to Lumma. The operator also described continued updates to evade Microsoft Defender and Chrome security controls, and claimed plans for a fake Ledger Live application to capture cryptocurrency seed phrases, operator-panel AI features, and additional security bypasses.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Remus was reportedly made available for public sale as a malware-as-a-service information stealer. Its operator later claimed the service had about 200 active customers.
Gen Threat Labs observed the first Remus infostealer campaigns around January to February 2026, with the report specifically dating campaigns back to February. The malware was described as a 64-bit evolutionary variant of Lumma rather than a replacement for it.
Observed Tenzor transitional samples carried an embedded build date of September 16, 2025. The samples contained traits and strings linking Lumma and the later Remus codebase.
Alleged core members of the Lumma Stealer operation were doxxed during a period spanning late August through October 2025. Gen Threat Labs said Tenzor development coincided with this period.
The Remus operator said the developers acquired Tensor source code and a VueJS panel, then substantially reworked the malware and replaced the panel code. The operator characterized Tensor as an apparent continuation or variant of Lumma Stealer.
Gen Threat Labs identified Remus and transitional Tenzor samples as Lumma Stealer variants, citing shared string obfuscation, anti-VM checks, syscall handling, control-flow obfuscation, and an Application-Bound Encryption bypass. The researchers also found that Remus replaced Lumma's Steam and Telegram dead-drop resolvers with Ethereum-based EtherHiding for runtime C2 resolution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 103 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcegendigital.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.