logo

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

ID: a4c4a106-d7be-5ecb-bbb2-9a513b099b00

STIX ID: report--a4c4a106-d7be-5ecb-bbb2-9a513b099b00

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Sponsored by Flare

...
...

Flare's analysis examines the REMUS infostealer and the underground MaaS operation behind it, documenting a rapid development cycle from February–May 2026 that added browser credential and cookie theft, token restoration, SOCKS5/proxy support, IndexedDB collection targeting password managers (1Password, LastPass, Bitwarden), and operational tooling (dashboards, worker tracking, delivery optimizations). The report highlights a shift from simple credential harvesting toward session theft and authenticated-session monetization, noting REMUS's commercialization, operational maturity, and focus on preserving and restoring authenticated access to bypass MFA and other protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.