logo

Remus Hides Its Command Server on Ethereum While Emptying Browser Vaults

ID: 53a8ca3e-6f76-55a8-975b-a8394c512100

STIX ID: report--53a8ca3e-6f76-55a8-975b-a8394c512100

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Tushar Subhra Dutta

...
...

Remus is an active Windows infostealer distributed through SEO‑poisoned warez storefronts (notably Turkish‑language fake cracked software sites) that injects into Chromium‑based browsers to steal saved passwords, cookies, crypto extension data, clipboard contents, FTP credentials, screenshots and email storage. The malware resolves its command-and-control dynamically by querying an Ethereum smart contract for the live C2 URL, then exfiltrates data via HTTP POSTs to rotating domains/IPs (numerous IoCs and SHA256 samples are provided); defenders are advised to block listed domains/IPs, monitor for process injection and unusual blockchain RPC requests, and avoid pirated software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.