logo

Remus Malware Bypasses Browser Application-Bound Encryption Protections

ID: 70246f7e-94df-53be-917c-88100307835f

STIX ID: report--70246f7e-94df-53be-917c-88100307835f

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Varshini

...
...

Remus is a sophisticated 64-bit information-stealer derived from the Lumma stealer that uses injected 51-byte shellcode to bypass Chromium Application-Bound Encryption and employs Ethereum smart contracts ("EtherHiding") for resilient C2 resolution; it includes advanced anti-analysis checks, is actively observed in campaigns since early 2026, and has published IOCs for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.