Remus Stealer is a 64-bit Windows information-stealing malware publicly observed in February 2026 and marketed through underground cybercriminal communities as a malware-as-a-service offering. It shares substantial similarities with Lumma Stealer in administration-panel design, stolen-log organization, string and control-flow obfuscation, and customer build identifiers, although these similarities do not establish that it is a rebrand. Its commercial features include Google OAuth cookie restoration and Telegram integration for stolen logs.
Remus collects credentials, session cookies, payment information, browsing history, and extension data from more than 20 browsers, alongside cryptocurrency wallet artifacts, authenticator data, and password-manager information. It also targets Roblox cookies and Steam authentication material, captures clipboard contents and screenshots, and inventories hardware, operating-system details, installed software, running processes, and security products. Chromium app-bound encryption bypass methods include SYSTEM-token impersonation, cryptographic key access, and code execution within a browser process. Operator-directed tasks support additional file and registry collection, screenshots, and arbitrary command or payload execution.
The malware uses runtime string decoding, API hashing, control-flow obfuscation, and checks for analysis modules and honeypot artifacts. Its command-and-control workflow attempts multiple endpoints and can use Ethereum smart contracts through EtherHiding to recover fallback infrastructure. Successful registration provides an access token for encrypted configuration retrieval, task polling, and data uploads. Collected artifacts are compressed and encrypted with ChaCha20 before exfiltration.
Distribution includes SEO-poisoned websites impersonating open-source and freeware projects, selectively gated traffic distribution systems, fake game-cheat repositories on GitHub, and ClickFix prompts on compromised websites. Observed delivery chains use PowerShell, AutoIt, Donut shellcode, or Go loaders to execute Remus in memory. Campaigns have targeted gamers and users downloading developer, reverse-engineering, and security tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Par ailleurs, les opérateurs ont été observés exploitant la vulnérabilité « CVE-2026-41089 » pour obtenir un accès non autorisé aux systèmes avant d'y installer le malware. | Remus Stealer est un malware de type Infostealer apparu en février 2026. Il appartient à la famille « Lumma Stealer »... Le malware cible notamment les identifiants et mots de passe enregistrés dans les navigateurs Web, les cookies de session, les historiques de navigation, les informations bancaires sauvegardées, les portefeuilles de cryptomonnaies, les jetons d'authentification (tokens)...
37 distinct techniques documented for this family, organized by ATT&CK tactic.
The ClickFix command executes a remote script named update.ps1, a consistent filename used by this campaign.
The downloaded installer is pre-bundled with AutoIt3.exe, which drops and loads an .au3 script from the same folder location.
The stealer extensively uses NtCreateFile, NtQueryDirectoryFile, NtReadFile, NtOpenProcess, NtReadVirtualMemory, NtCreateThreadEx, and other native APIs/syscalls.
The embedded JavaScript loader is using an indexed string table to dynamically resolve property names.
Fake GitHub cheat repositories and a GitHub Pages site advertise a Meccha Chameleon cheat but deliver an NSIS installer and infostealer.
Below are the observed executable filenames: data_work.exe | current-cache.exe | audio-music.exe | download-package.exe
To recover Chromium app-bound encryption keys, Remus opens a browser process, writes a CryptUnprotectMemory stub into allocated RWX memory, and executes it using NtCreateThreadEx.
The extracted shellcode is injected into the same AutoIt process.
Uses the derived key and retrieved IV to decrypt the configuration, producing a Base64-encoded domain.
Operators can issue tasks to retrieve specified registry values; Remus also enumerates Uninstall keys and queries the Steam InstallPath registry value.
Queries a PHP endpoint to obtain the visitor's IP address and country code.
Running processes are enumerated to locate SYSTEM processes with SeImpersonatePrivilege, active browser processes, Steam processes, and to generate Processes.txt.
Observed queries include: "SELECT * FROM Win32_OperatingSystem" and "SELECT * FROM Win32_VideoController".
Visitor Registration — Constructs a visitor-specific JSON record containing the unique identifier, IP address, originating domain, User-Agent, country code, and browser language.
Observed targeting extends across the following categories: Applications, Wallets, Chromium-Based Browsers, Mozilla-Based Browsers, Authenticator and 2FA, Password manager.
The resulting collected host and environment information are then saved to Info.yml.
Captures the entire virtual desktop (all monitors) via GDI and encodes as a 32bpp BMP, appended to the exfiltration collection.
Active clipboard text is captured with GetClipboardData and included as Clipboard.txt.
WinHttpConnect, WinHttpOpenRequest (POST method), WinHttpSendRequest ... WinHttpReceiveResponse, WinHttpReadData
If its three configured C2 domains fail, Remus queries an Ethereum JSON-RPC endpoint and contract to recover a fallback C2 domain.
397 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information stealer delivered through the PhantomPolia and ClickFix infection chain. Collects host information, credentials, browser data, password-manager artifacts, cryptocurrency wallets, authentication data, and desktop screenshots. Uses a registration and session-token exchange before exfiltration. Stolen data is compressed with a custom LZ77 implementation and encrypted with ChaCha20; the encryption key and nonce are appended to the transmitted blob, permitting decryption of captured traffic. Researchers characterize it as a potential successor to Lumma based on similarities.
Mentioned as an example of malware delivered in a separate SEO poisoning campaign imitating open-source and freeware projects.
Mentioned as an example of malware delivered in a separate SEO poisoning campaign impersonating open-source and freeware projects.
Mentioned as the apparent inspiration for Amatera's redesigned ABE bypass.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.