Remus Malware Bypasses Browser Application-Bound Encryption Protections
ID: 70246f7e-94df-53be-917c-88100307835f
STIX ID: report--70246f7e-94df-53be-917c-88100307835f
Feed Name: Cyber Press
Threat Score
Remus is a sophisticated 64-bit information-stealer derived from the Lumma stealer that uses injected 51-byte shellcode to bypass Chromium Application-Bound Encryption and employs Ethereum smart contracts ("EtherHiding") for resilient C2 resolution; it includes advanced anti-analysis checks, is actively observed in campaigns since early 2026, and has published IOCs for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
