Remus Malware Bypasses Browser Application-Bound Encryption Protections

The cybersecurity landscape is facing a sophisticated new threat with the discovery of Remus, a highly advanced 64-bit information-stealing malware.

Security researchers at Gen Threat Labs have identified Remus as a direct evolution of the notorious Lumma Stealer.

Following the public doxxing of alleged Lumma core members between August and October 2025, developers seemingly regrouped to create this next-generation variant.

Test builds labeled as Tenzor first appeared in September 2025, acting as a structural bridge before Remus officially began circulating in live campaigns by February 2026.

While active Lumma campaigns persist globally, Remus represents a continuous evolution rather than a complete replacement. This new variant brings a formidable arsenal capable of stealing stored browser passwords, session cookies, and cryptocurrency wallets.

Remus Bypasses Browser Encryption

One of the most definitive links between Remus and its predecessor is a highly specific method used to bypass Application-Bound Encryption in Chromium-based browsers.

Instead of relying on standard extraction techniques, Remus injects a custom, lightweight 51-byte shellcode directly into the memory space of the browser process.

This shellcode actively hunts for the protected master key, known as the v20_master_key, which browsers safeguard in memory at runtime.

The string testbuild present in a Tenzor sample (Source: gendigital)
The string testbuild present in a Tenzor sample (Source: gendigital)

Beyond its credential theft capabilities, Remus introduces novel techniques that surpass a simple 64-bit port of older code. The most significant architectural shift is its adoption of EtherHiding for command-and-control resolution.

Previous Lumma versions relied on traditional dead drop resolvers hosted on Steam profiles or Telegram channels.

In contrast, Remus utilizes Ethereum smart contracts hosted on the blockchain to hide its malicious infrastructure. By sending a request to a hardcoded smart contract address, the malware retrieves a hex-encoded response containing the active server URL.

Decrypted LOG strings in Tenzor (left) and Remus (right) (Source: gendigital)
Decrypted LOG strings in Tenzor (left) and Remus (right) (Source: gendigital)

Because blockchain records are decentralized and immutable, this tactic makes the infrastructure practically immune to standard takedown requests.

Decryption of the string “Processes.txt” in Remus (left) and Lumma (right) (Source: gendigital)
Decryption of the string “Processes.txt” in Remus (left) and Lumma (right) (Source: gendigital)

Gen Digital explain, Remus employs rigorous new anti-analysis checks to evade detection by security researchers. During its initial startup phase, the malware scans the system for known sandbox and analysis dynamic link libraries, including those used by Avast and Comodo security products.

It also checks document folders for specific honeypot files that indicate a controlled testing environment. If any of these defensive triggers are activated, the malware immediately and silently terminates its own process.

These extensive evasion tactics, combined with an already proven credential theft engine, make Remus a highly resilient threat that requires immediate attention from security defenders worldwide.

Indicators of Compromise

IOC TypeIOC ValueContext
IP / Port217[.]156[.]122[.]12:80C2 Server
IP / Port217[.]156[.]122[.]57:80C2 Server
IP / Port217[.]156[.]122[.]75:1378C2 Server
IP / Port45[.]151[.]106[.]110:80C2 Server

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories