RemusStealer: EtherHiding In Hidden Windows
RemusStealer is a malware-as-a-service program exhibiting multiple similarities to LummaStealer, including anti-virtual machine checks, credential theft tactics, and Application-Bound Encryption bypass methods. A key distinction is RemusStealer's use of Ethereum smart contracts for C2 communications instead of Steam or Telegram dead drop resolvers. Written in Go, the stealer performs extensive system discovery, gathering information about antivirus products, hardware specifications, and operating systems. It employs hidden desktop environments to evade detection while launching Microsoft Edge and Brave browser processes on non-primary window stations to steal credential files. The malware establishes connections to suspicious domains ending in .shop or .biz and communicates with Ethereum-related infrastructure. This evolution demonstrates attackers' increasing sophistication in leveraging blockchain technology to masquerade malicious communications through smart contracts.
AI Analysis
Technical Summary
RemusStealer is a Go-based malware-as-a-service program designed to steal credentials and system information. It exhibits anti-virtual machine detection, bypasses Application-Bound Encryption, and performs detailed system discovery including antivirus, hardware, and OS data collection. Unlike similar malware that uses Steam or Telegram for C2, RemusStealer uses Ethereum smart contracts for command and control, representing an evolution in attacker sophistication by leveraging blockchain technology. It employs hidden desktop environments and launches browser processes on non-primary window stations to evade detection and steal credential files. The malware communicates with suspicious domains ending in .shop or .biz and interacts with Ethereum-related infrastructure for C2.
Potential Impact
The malware enables attackers to steal credentials and system information stealthily, potentially compromising user accounts and sensitive data. Its use of Ethereum smart contracts for C2 communications complicates detection and attribution. The hidden desktop technique and launching of browsers on non-primary window stations increase its ability to evade security controls. There are no reports of active exploitation in the wild at this time.
Mitigation Recommendations
No official patches or vendor advisories are available for RemusStealer. Defenders should monitor for indicators such as connections to suspicious .shop or .biz domains (e.g., shivlpf.shop) and unusual browser processes running on non-primary window stations. Employ endpoint detection tools capable of identifying hidden desktop environments and credential theft behaviors. Since this is malware, standard endpoint protection and threat intelligence updates are recommended. Patch status is not applicable.
Indicators of Compromise
- domain: shivlpf.shop
RemusStealer: EtherHiding In Hidden Windows
Description
RemusStealer is a malware-as-a-service program exhibiting multiple similarities to LummaStealer, including anti-virtual machine checks, credential theft tactics, and Application-Bound Encryption bypass methods. A key distinction is RemusStealer's use of Ethereum smart contracts for C2 communications instead of Steam or Telegram dead drop resolvers. Written in Go, the stealer performs extensive system discovery, gathering information about antivirus products, hardware specifications, and operating systems. It employs hidden desktop environments to evade detection while launching Microsoft Edge and Brave browser processes on non-primary window stations to steal credential files. The malware establishes connections to suspicious domains ending in .shop or .biz and communicates with Ethereum-related infrastructure. This evolution demonstrates attackers' increasing sophistication in leveraging blockchain technology to masquerade malicious communications through smart contracts.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RemusStealer is a Go-based malware-as-a-service program designed to steal credentials and system information. It exhibits anti-virtual machine detection, bypasses Application-Bound Encryption, and performs detailed system discovery including antivirus, hardware, and OS data collection. Unlike similar malware that uses Steam or Telegram for C2, RemusStealer uses Ethereum smart contracts for command and control, representing an evolution in attacker sophistication by leveraging blockchain technology. It employs hidden desktop environments and launches browser processes on non-primary window stations to evade detection and steal credential files. The malware communicates with suspicious domains ending in .shop or .biz and interacts with Ethereum-related infrastructure for C2.
Potential Impact
The malware enables attackers to steal credentials and system information stealthily, potentially compromising user accounts and sensitive data. Its use of Ethereum smart contracts for C2 communications complicates detection and attribution. The hidden desktop technique and launching of browsers on non-primary window stations increase its ability to evade security controls. There are no reports of active exploitation in the wild at this time.
Defensive Guidance
No official patches or vendor advisories are available for RemusStealer. Defenders should monitor for indicators such as connections to suspicious .shop or .biz domains (e.g., shivlpf.shop) and unusual browser processes running on non-primary window stations. Employ endpoint detection tools capable of identifying hidden desktop environments and credential theft behaviors. Since this is malware, standard endpoint protection and threat intelligence updates are recommended. Patch status is not applicable.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://binarydefense.com/resources/blog/remusstealer-etherhiding-in-hidden-windows"]
- Pulse Id
- 6abf0d2f3741a634cbd57475
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainshivlpf.shop | — |
Threat ID: 6abf6144a43b0b3b898aa714
Added to database: 10/02/2026, 07:46:12 UTC
Last enriched: 10/02/2026, 08:03:10 UTC
Last updated: 10/02/2026, 19:33:43 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.