Skip to main content

RemusStealer: EtherHiding In Hidden Windows

0
Medium
Published: 10/02/2026 (10/02/2026, 01:47:27 UTC)
Source: AlienVault OTX General

Description

RemusStealer is a malware-as-a-service program exhibiting multiple similarities to LummaStealer, including anti-virtual machine checks, credential theft tactics, and Application-Bound Encryption bypass methods. A key distinction is RemusStealer's use of Ethereum smart contracts for C2 communications instead of Steam or Telegram dead drop resolvers. Written in Go, the stealer performs extensive system discovery, gathering information about antivirus products, hardware specifications, and operating systems. It employs hidden desktop environments to evade detection while launching Microsoft Edge and Brave browser processes on non-primary window stations to steal credential files. The malware establishes connections to suspicious domains ending in .shop or .biz and communicates with Ethereum-related infrastructure. This evolution demonstrates attackers' increasing sophistication in leveraging blockchain technology to masquerade malicious communications through smart contracts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/02/2026, 08:03:10 UTC

Technical Analysis

RemusStealer is a Go-based malware-as-a-service program designed to steal credentials and system information. It exhibits anti-virtual machine detection, bypasses Application-Bound Encryption, and performs detailed system discovery including antivirus, hardware, and OS data collection. Unlike similar malware that uses Steam or Telegram for C2, RemusStealer uses Ethereum smart contracts for command and control, representing an evolution in attacker sophistication by leveraging blockchain technology. It employs hidden desktop environments and launches browser processes on non-primary window stations to evade detection and steal credential files. The malware communicates with suspicious domains ending in .shop or .biz and interacts with Ethereum-related infrastructure for C2.

Potential Impact

The malware enables attackers to steal credentials and system information stealthily, potentially compromising user accounts and sensitive data. Its use of Ethereum smart contracts for C2 communications complicates detection and attribution. The hidden desktop technique and launching of browsers on non-primary window stations increase its ability to evade security controls. There are no reports of active exploitation in the wild at this time.

Defensive Guidance

No official patches or vendor advisories are available for RemusStealer. Defenders should monitor for indicators such as connections to suspicious .shop or .biz domains (e.g., shivlpf.shop) and unusual browser processes running on non-primary window stations. Employ endpoint detection tools capable of identifying hidden desktop environments and credential theft behaviors. Since this is malware, standard endpoint protection and threat intelligence updates are recommended. Patch status is not applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://binarydefense.com/resources/blog/remusstealer-etherhiding-in-hidden-windows"]
Pulse Id
6abf0d2f3741a634cbd57475

Indicators of Compromise

Domain

ValueDescriptionCopy
domainshivlpf.shop
—

Threat ID: 6abf6144a43b0b3b898aa714

Added to database: 10/02/2026, 07:46:12 UTC

Last enriched: 10/02/2026, 08:03:10 UTC

Last updated: 10/02/2026, 19:33:43 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses