logo

Mapping Remus Infostealer

ID: 20e4d3c5-ea90-5290-934a-3d186f26c75a

STIX ID: report--20e4d3c5-ea90-5290-934a-3d186f26c75a

Feed Name: IntelInsights (Substack)

Threat Score
72/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Vasilis Orlof

...
...

This report examines the Remus infostealer infrastructure: a distributed cluster spanning >15 ASNs with concentration at Hostinger (AS47583) and Team Internet (AS206834), numerous .biz domains registered in early March (Dynadot), shared certificate fingerprints, and pivotable IoCs. The author correlates domain/cert pivots with Ethereum on-chain evidence, uncovering five smart contracts (one DomainStorage and four DataStore versions) used to store C2 URLs; contract versions show evolving validation, event logging changes, and a gas-optimization comment in Russian suggesting a language fingerprint. The findings support an automated campaign with active operator iteration and provide detection hooks (on-chain event monitors, IoCs) while noting attribution remains limited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.