Skip to main content

Remus Stealer - 64bit evolution of Lumma

0
Medium
Published: 06/15/2026 (06/15/2026, 20:52:40 UTC)
Source: Reddit Malware

Description

Remus Stealer is a 64-bit malware evolution of Lumma Stealer that emerged in 2026 as a Malware-as-a-Service infostealer. It targets credentials, browser cookies, authentication tokens, and cryptocurrency wallets, notably capable of stealing active session cookies to bypass multi-factor authentication. The malware uses advanced evasion techniques including EtherHiding, which stores command-and-control addresses in Ethereum smart contracts to avoid takedowns, and enhanced anti-analysis features such as sandbox DLL checks and PST honeypot detection. Infection vectors include phishing, fake software downloads, malvertising, fake CAPTCHA campaigns, SEO poisoning, and fake GitHub projects. It targets sectors like financial services, healthcare, government, technology firms, and managed service providers. No official patch or remediation is indicated, and no known exploits in the wild are reported yet.

Reddit Discussion

r/Malware·posted by u/rifteyy_
00

Remus Stealer is a rapidly evolving Malware-as-a-Service infostealer that emerged in 2026.

Remus also shifted from Lumma's 32-bit architecture and traditional resolvers to 64-bit with EtherHiding and enhanced anti-analysis (e.g., sandbox DLL checks, PST honeypot detection).

  • It utilizes EtherHiding, storing C2 addresses in Ethereum smart contracts to avoid takedowns.
  • The malware steals credentials, browser cookies, authentication tokens, and cryptocurrency wallet data.
  • Session theft is one of Remus's most dangerous capabilities because it can bypass MFA by stealing active session cookies directly from browser memory.
  • The malware shows strong technical similarities to Lumma Stealer and may represent its evolutionary successor.
  • Financial services, healthcare, government, technology firms, and MSPs are particularly attractive targets.
  • Common infection vectors include phishing, fake software downloads, malvertising, and fake CAPTCHA campaigns, as well as SEO poisoning and fake GitHub projects to trick tech-savvy users.

See whole ANY.RUN execution chain at https://app.any.run/tasks/ae43628b-9d56-4c43-abac-fae7266c749f/

Check out whole malware analysis report at https://any.run/malware-trends/remus/

Also discussed in: r/cybersecurity

Technical Details

Source Type
reddit
Subreddit
Malware
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
Has External Source
true
Trusted Domain
false

Threat ID: 6a318bb30b89be6888fa6ab0

Added to database: 06/16/2026, 17:45:23 UTC

Last enriched: 06/16/2026, 17:45:34 UTC

Last updated: 09/15/2026, 00:31:16 UTC

Views: 394

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses