Stairwell Emergence of Remus Stealer: A New Infostealer Threat
Article Content
- •Remus Stealer is a 64-bit infostealer that evolved from Lumma Stealer.
- •It uses advanced techniques like EtherHiding to evade detection.
- •Targets include financial services, healthcare, and government sectors.
Remus Stealer, a Malware-as-a-Service infostealer, emerged in 2026 as a successor to Lumma Stealer. It operates on a 64-bit architecture and employs advanced techniques like EtherHiding to store C2 addresses in Ethereum smart contracts. The malware targets financial services, healthcare, government, technology firms, and managed service providers (MSPs). It is capable of stealing credentials, browser cookies, authentication tokens, and cryptocurrency wallet data, with session theft being particularly dangerous as it can bypass multi-factor authentication (MFA). Infection vectors include phishing, fake software downloads, malvertising, and SEO poisoning. Remus has been growing in capabilities since its discovery in February 2026, indicating a significant threat landscape for organizations. Current defenses and detection methods are still being developed to counter this evolving threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Lumma Stealer and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SectopRAT Variant Exploits Legitimate Software for Remote Control Attacks A new variant of the SectopRAT remote access Trojan (RAT) has been discovered embedded in legitimate software from an Italian digital audio company. This multi-stage attack allows attackers to gain full remote control of Windows systems by concealing the malware within modified application components. The malware is…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…