Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
ID: a4c4a106-d7be-5ecb-bbb2-9a513b099b00
STIX ID: report--a4c4a106-d7be-5ecb-bbb2-9a513b099b00
Feed Name: Bleeping Computer
Flare's analysis examines the REMUS infostealer and the underground MaaS operation behind it, documenting a rapid development cycle from February–May 2026 that added browser credential and cookie theft, token restoration, SOCKS5/proxy support, IndexedDB collection targeting password managers (1Password, LastPass, Bitwarden), and operational tooling (dashboards, worker tracking, delivery optimizations). The report highlights a shift from simple credential harvesting toward session theft and authenticated-session monetization, noting REMUS's commercialization, operational maturity, and focus on preserving and restoring authenticated access to bypass MFA and other protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
