Remus is a Windows information-stealing malware family that emerged in early 2026 and is widely assessed as closely derived from, or an evolutionary branch of, Lumma Stealer. It is commonly described as a 64-bit variant with substantial code and tradecraft overlap, including similar browser-focused credential theft and techniques for bypassing Chromium protections. Remus has also been marketed and operated as a malware-as-a-service offering, with rapid feature development, operator support, and infrastructure designed for scalable criminal use.
Remus primarily targets browser-stored secrets and authenticated access artifacts. Its core collection includes saved passwords, cookies, browser vault data, and cryptocurrency wallet-related data. Reported variants and campaigns also target password manager artifacts, FTP client credentials, gaming platform data, clipboard contents, screenshots, enterprise email storage files, and selected browser extension data. Underground reporting further indicates an emphasis on session theft and restore-token abuse, reflecting a shift from simple credential harvesting toward persistent authenticated access and session hijacking.
A notable technical characteristic is its handling of Chromium-based browsers. Remus injects into live browser processes and accesses browser data in-process. It has been reported to read encrypted browser master-key material and to use browser-memory techniques associated with Application-Bound Encryption bypass, enabling decryption of protected browser secrets. If direct browser-process access fails, some builds reportedly launch a hidden browser instance on a separate desktop to recover the necessary key material. This design supports offline decryption of exfiltrated browser databases and improves resilience against browser hardening.
Remus exfiltrates stolen data over HTTP POST and has been observed disguising outbound traffic as benign telemetry or diagnostic traffic. Its command-and-control design is notable for using blockchain-based dead-drop resolution, specifically EtherHiding-style retrieval of live infrastructure from Ethereum smart contracts, allowing operators to rotate backend servers without rebuilding the malware. Reporting also notes anti-analysis checks and continued development of delivery, management, and operator-visibility features.
Observed distribution is heavily tied to fake cracked-software and warez ecosystems, especially SEO-poisoned sites impersonating pirated tools and games. Turkish-language lures have been repeatedly observed, suggesting significant targeting of Turkish users in some campaigns. Remus has also appeared in broader ClickFix and malicious traffic-distribution operations alongside other stealers and loaders, and has been delivered by intermediary malware such as GoFlateLoader. Shared hosting and distribution infrastructure with other infostealers indicates that Remus is often part of multi-family cybercrime delivery networks rather than a standalone campaign.
Remus is significant both as an active infostealer and as an indicator of the professionalization of the stealer ecosystem. Its evolution toward session persistence, password-manager-related collection, dynamic C2 resolution, and service-style commercialization places it among the more mature credential- and session-theft platforms active in 2026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
As a result, users unknowingly execute a malicious PowerShell command, enabling malicious loaders to be launched at the next stage on the device.
Obfuscation and encryption for the injected ErrTraffic script (using AES and JavaScript obfuscation).
Observations indicate that such campaigns make use of fake interfaces impersonating Google reCAPTCHA and Cloudflare verification pages, as well as deceptive pages associated with Google Meet, QR code services and other well-known platforms.
Once a victim extracts the fake archive and runs the bundled executable, Remus injects into running Chromium-based browsers using remote threads.
It reads the OS-level encrypted master keys from local state files, retrieves AES keys and application-data protection master keys, and then uses those to decrypt saved passwords and other credentials offline.
SockS5 proxy integration, antivirtualization controls, gaming-platform targeting, as well as deeper password harvesting were all added to the malware.
From there, it can access browser vaults directly, harvesting saved passwords, session cookies, and sensitive data that would normally be locked behind encryption on disk.
The final payloads GoFlateLoader delivers are all information stealers, programs designed to quietly harvest saved passwords, browser data, and cryptocurrency wallet credentials from infected machines.
From there, it can access browser vaults directly, harvesting saved passwords, session cookies, and sensitive data that would normally be locked behind encryption on disk.
Initially focused on browser credential theft and basic log management
This objective was further reinforced by repeated targeting of Discord, Steam, Riot Games, and Telegram environments... As of April 2026, the operator has implemented collection capabilities associated with Bitwarden, 1Password, LastPass, and IndexedDB-based browser storage mechanisms commonly used to retain locally authenticated data...
It scans for DLLs linked to known analysis platforms and checks for a specific honeypot file on disk.
April marked another strategic transition in REMUS's evolution, this time toward authentication-based session persistence and browser-side artifact collection... It also included IndexedDB extractions linked to browser extensions associated with the 1Password and LastPass browser extensions...
A type of advanced remote access Trojan called an infostealer operates silently within infected systems, gathering cookies, authentication tokens, stored passwords, fingerprints, and other telemetry from the infected system before packaging the information into standardized 'stealer logs' for exfiltration.
The malware also forges the HTTP Host header to mimic a major technology vendor, which helps outbound traffic blend in with normal telemetry and reduces the chance that simple filtering rules will catch it.
Started as a single Ethereum contract which expanded into a cluster of 5 contracts, multiple operator wallets... The development started with the basic DomainStorage with no validation moved to the hardened DataStore variants.
That URL then becomes the destination for the stolen data, pushed via HTTP POST requests that disguise the payload as diagnostic or telemetry logs.
SockS5 proxy integration... was added to the malware... There were repeated references throughout the campaign to 'Restore' capabilities, multi-proxy compatibility, and token recovery workflows...
ErrTraffic v3, documented by LevelBlue in April 2026, uses the EtherHiding technique as DDR. The injected script on compromised WordPress sites queries a smart contract on a blockchain to retrieve the ErrTraffic C2 server.
269 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential/data stealing malware with victim check-in and POST exfiltration behavior, dropped as Veritaseum.exe.
A 64-bit variant of Lumma Stealer delivered through fake websites using cracked software and pirated game lures.
A newly active Windows infostealer distributed via fake cracked software sites. It injects into Chromium-based browsers using remote threads, steals saved passwords, cookies, crypto wallet data, password manager contents, FTP credentials, clipboard data, screenshots, and enterprise email storage files. It resolves its active C2 by querying an Ethereum smart contract and then exfiltrates stolen data over HTTP POST.
An infostealer distributed via fake cracked software sites that injects into Chromium-based browsers to steal browser credentials, gaming platform data, FTP credentials, clipboard contents, screenshots, and enterprise email files. It dynamically resolves command-and-control from an Ethereum smart contract and disguises exfiltration using spoofed Host headers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.