Remus Stealer - 64bit evolution of Lumma
Remus Stealer is a 64-bit malware evolution of Lumma Stealer that emerged in 2026 as a Malware-as-a-Service infostealer. It targets credentials, browser cookies, authentication tokens, and cryptocurrency wallets, notably capable of stealing active session cookies to bypass multi-factor authentication. The malware uses advanced evasion techniques including EtherHiding, which stores command-and-control addresses in Ethereum smart contracts to avoid takedowns, and enhanced anti-analysis features such as sandbox DLL checks and PST honeypot detection. Infection vectors include phishing, fake software downloads, malvertising, fake CAPTCHA campaigns, SEO poisoning, and fake GitHub projects. It targets sectors like financial services, healthcare, government, technology firms, and managed service providers. No official patch or remediation is indicated, and no known exploits in the wild are reported yet.
Remus Stealer - 64bit evolution of Lumma
Description
Remus Stealer is a 64-bit malware evolution of Lumma Stealer that emerged in 2026 as a Malware-as-a-Service infostealer. It targets credentials, browser cookies, authentication tokens, and cryptocurrency wallets, notably capable of stealing active session cookies to bypass multi-factor authentication. The malware uses advanced evasion techniques including EtherHiding, which stores command-and-control addresses in Ethereum smart contracts to avoid takedowns, and enhanced anti-analysis features such as sandbox DLL checks and PST honeypot detection. Infection vectors include phishing, fake software downloads, malvertising, fake CAPTCHA campaigns, SEO poisoning, and fake GitHub projects. It targets sectors like financial services, healthcare, government, technology firms, and managed service providers. No official patch or remediation is indicated, and no known exploits in the wild are reported yet.
Reddit Discussion
Remus Stealer is a rapidly evolving Malware-as-a-Service infostealer that emerged in 2026.
Remus also shifted from Lumma's 32-bit architecture and traditional resolvers to 64-bit with EtherHiding and enhanced anti-analysis (e.g., sandbox DLL checks, PST honeypot detection).
- It utilizes EtherHiding, storing C2 addresses in Ethereum smart contracts to avoid takedowns.
- The malware steals credentials, browser cookies, authentication tokens, and cryptocurrency wallet data.
- Session theft is one of Remus's most dangerous capabilities because it can bypass MFA by stealing active session cookies directly from browser memory.
- The malware shows strong technical similarities to Lumma Stealer and may represent its evolutionary successor.
- Financial services, healthcare, government, technology firms, and MSPs are particularly attractive targets.
- Common infection vectors include phishing, fake software downloads, malvertising, and fake CAPTCHA campaigns, as well as SEO poisoning and fake GitHub projects to trick tech-savvy users.
See whole ANY.RUN execution chain at https://app.any.run/tasks/ae43628b-9d56-4c43-abac-fae7266c749f/
Check out whole malware analysis report at https://any.run/malware-trends/remus/
Links cited in this discussion
Technical Details
- Source Type
- Subreddit
- Malware
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":35,"reasons":["external_link","established_author","recent_news"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6a318bb30b89be6888fa6ab0
Added to database: 06/16/2026, 17:45:23 UTC
Last enriched: 06/16/2026, 17:45:34 UTC
Last updated: 09/15/2026, 00:31:16 UTC
Views: 394
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.