The cybersecurity landscape is facing a sophisticated new threat with the discovery of Remus, a highly advanced 64-bit information-stealing malware.
Security researchers at Gen Threat Labs have identified Remus as a direct evolution of the notorious Lumma Stealer.
Following the public doxxing of alleged Lumma core members between August and October 2025, developers seemingly regrouped to create this next-generation variant.
Test builds labeled as Tenzor first appeared in September 2025, acting as a structural bridge before Remus officially began circulating in live campaigns by February 2026.
While active Lumma campaigns persist globally, Remus represents a continuous evolution rather than a complete replacement. This new variant brings a formidable arsenal capable of stealing stored browser passwords, session cookies, and cryptocurrency wallets.
Remus Bypasses Browser Encryption
One of the most definitive links between Remus and its predecessor is a highly specific method used to bypass Application-Bound Encryption in Chromium-based browsers.
Instead of relying on standard extraction techniques, Remus injects a custom, lightweight 51-byte shellcode directly into the memory space of the browser process.
This shellcode actively hunts for the protected master key, known as the v20_master_key, which browsers safeguard in memory at runtime.

Beyond its credential theft capabilities, Remus introduces novel techniques that surpass a simple 64-bit port of older code. The most significant architectural shift is its adoption of EtherHiding for command-and-control resolution.
Previous Lumma versions relied on traditional dead drop resolvers hosted on Steam profiles or Telegram channels.
In contrast, Remus utilizes Ethereum smart contracts hosted on the blockchain to hide its malicious infrastructure. By sending a request to a hardcoded smart contract address, the malware retrieves a hex-encoded response containing the active server URL.

Because blockchain records are decentralized and immutable, this tactic makes the infrastructure practically immune to standard takedown requests.

Gen Digital explain, Remus employs rigorous new anti-analysis checks to evade detection by security researchers. During its initial startup phase, the malware scans the system for known sandbox and analysis dynamic link libraries, including those used by Avast and Comodo security products.
It also checks document folders for specific honeypot files that indicate a controlled testing environment. If any of these defensive triggers are activated, the malware immediately and silently terminates its own process.
These extensive evasion tactics, combined with an already proven credential theft engine, make Remus a highly resilient threat that requires immediate attention from security defenders worldwide.
Indicators of Compromise
| IOC Type | IOC Value | Context |
|---|---|---|
| IP / Port | 217[.]156[.]122[.]12:80 | C2 Server |
| IP / Port | 217[.]156[.]122[.]57:80 | C2 Server |
| IP / Port | 217[.]156[.]122[.]75:1378 | C2 Server |
| IP / Port | 45[.]151[.]106[.]110:80 | C2 Server |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.