Remus is a Windows information stealer marketed through a malware-as-a-service affiliate model since early 2026. Affiliates generate customized payloads and operate separate distribution infrastructure. Remus exhibits code-obfuscation, system-call, and browser credential-extraction similarities to Lumma Stealer. It collects saved passwords, browser cookies, authenticated session tokens, browser encryption keys, cryptocurrency-wallet data, clipboard contents, screenshots, and selected files. Its targets include Chromium- and Mozilla-based browsers, password managers, authentication extensions, and remote-access, VPN, messaging, cloud, and file-transfer applications. Stolen cookies and tokens enable session hijacking without repeating password or MFA challenges.
Remus also targets locally stored AI-assistant and coding-agent data, including artifacts associated with Claude, Cursor, and OpenCode. Collection includes credentials, API tokens, and usage histories, potentially exposing sensitive development context and connected-service access. This activity follows endpoint compromise rather than exploitation of vulnerabilities in the AI tools. Distribution includes ClickFix fake-CAPTCHA lures, malicious advertisements, compromised websites, and trojanized cracked software or games. Observed delivery chains use PLYCHIP, DonutLoader, GoFlateLoader, and 2CLoader; some execute the Remus payload entirely in memory.
Remus uses browser-process injection to obtain protected browser data. Its evasion mechanisms include OLLVM-based obfuscation, encrypted system-call reference tables, direct system calls, removal of endpoint-monitoring hooks, and sandbox checks. It profiles compromised systems and installed security products through Windows interfaces, including COM objects. Embedded command-and-control configuration and stolen data are protected with ChaCha20, and exfiltration occurs through staged HTTP POST requests. Supported configurations use EtherHiding to retrieve replacement command-and-control locations from Ethereum smart contracts when embedded infrastructure is unavailable.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The loader then uses process hollowing to place the Remus stealer inside ServiceModelReg.exe.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Targeted pivoting on one-verif[.]lol ... yielded several PowerShell samples ... [that] confirmed the Remus payload was decrypted and executed entirely within the PowerShell process's own memory.
The sample also carried the syscall.Syscall execution transfer abuse by pointing to the Remus payload's entry point.
The ClickFix clipboard-hijack JavaScript ... writes [a] command to the victim's clipboard ... [and] directs victims to one-verif[.]lol.
Remus payloads protect their embedded C2 configuration with the ChaCha20 encryption algorithm.
The threat actors append data beyond the PE's default section table with null or random bytes to artificially inflate the size of the file, also known as a 'PE overlay.'
The report includes cases involving disguising as cracks and keygens... Statistics on companies disguised by new malware... were extracted based on version and certificate information.
Remus targets Chromium and Firefox browser credentials, cookies, and master keys via browser-process injection.
“[Remus] keeps [system-call numbers] in a reference table that it decrypts in memory during setup.”
Remus prioritizes stealing authenticated browser sessions to bypass multi-factor authentication (MFA).
“The malware can also gather data from remote access, VPN, cloud, messaging, and file-transfer applications.”
“Remus also has the ability to steal data from registry entries in order to gather additional information about victim software installations.”
“The stealer also uses generic Windows COM objects to profile a device.”
Remus registers with its C2 over HTTP on non-standard ports then exfiltrates via multipart POST.
“It communicates with a changing server address obtained through an Ethereum smart contract, a method called EtherHiding.”
A loader already on the victim's computer fetches ... blobs directly from a bare IP on TCP/5000 ... [or] retrieves a loader PE first.
“It communicates with a changing server address obtained through an Ethereum smart contract, a method called EtherHiding.”
287 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a prevalent information-stealer family for comparison with Warden Stealer, not as a component of the Warden infection chain.
Information-stealer family mentioned as a comparison with Warden Stealer, not as part of the reported Warden infection chain.
Mentioned as another prevalent infostealer and as a comparison for Warden Stealer's Application-Bound Encryption bypass. It injects shellcode into the browser to invoke CryptUnprotectMemory and decrypt protected key material within the browser process.
Information stealer observed being delivered by 2CLoader. The content does not detail its collection capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.