logo

Remus Infostealer Debuts With Stealthy New Credential-Theft Tactics

ID: d597de01-58e4-5510-84ec-f2b09774dab0

STIX ID: report--d597de01-58e4-5510-84ec-f2b09774dab0

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Remus is a newly observed 64‑bit information stealer closely linked to the Lumma family via shared code patterns and test builds (Tenzor). It harvests browser credentials, cookies, autofill data, and crypto wallets, uses direct syscalls and an ABE bypass to extract Chromium master keys, employs EtherHiding C2 resolution via Ethereum smart-contract calls for resilient dead drops, and includes expanded anti‑analysis checks; campaigns were first seen in February 2026 and defenders are advised to update detections and monitor eth_call traffic, CryptUnprotectMemory usage, and suspicious browser process behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.