Remus Infostealer Debuts With Stealthy New Credential-Theft Tactics
ID: d597de01-58e4-5510-84ec-f2b09774dab0
STIX ID: report--d597de01-58e4-5510-84ec-f2b09774dab0
Feed Name: GBHackers
Remus is a newly observed 64‑bit information stealer closely linked to the Lumma family via shared code patterns and test builds (Tenzor). It harvests browser credentials, cookies, autofill data, and crypto wallets, uses direct syscalls and an ABE bypass to extract Chromium master keys, employs EtherHiding C2 resolution via Ethereum smart-contract calls for resilient dead drops, and includes expanded anti‑analysis checks; campaigns were first seen in February 2026 and defenders are advised to update detections and monitor eth_call traffic, CryptUnprotectMemory usage, and suspicious browser process behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
