CIS CTI tracked Remus infostealer distribution from March to September 2026, showing how the MaaS operation uses browser-session theft, EtherHiding C2 rotation, and multiple delivery chains to spread the payload. The investigation tied Remus to Lumma Stealer lineage and highlighted activity involving ClickFix, PLYCHIP, DonutLoader, GoFlateLoader, LandUpdate808, and domains such as fightwa[.]biz, robinhuds[.]com, and genuskox[.]biz. #Remus #LummaStealer #EtherHiding #ClickFix #PLYCHIP #DonutLoader #GoFlateLoader #LandUpdate808
Keypoints
- Remus infostealer distribution activity was observed across March through September 2026.
- The malware operates under a MaaS affiliate model with tiered subscriptions and customized binaries for each affiliate.
- Remus focuses on stealing authenticated browser sessions, cookies, credentials, and master keys to bypass MFA.
- CIS CTI identified three main delivery chains: ClickFix with PLYCHIP, DonutLoader shellcode delivery, and cracked-software bundling with GoFlateLoader.
- The operator can rotate C2 infrastructure through EtherHiding, which uses Ethereum smart contracts to fetch live endpoints.
- Remus also expanded collection to AI clients such as Claude, Codex, OpenCode, Cursor, and Devin.
- The campaign overlaps with Lumma Stealer lineage through the intermediate project Tenzor and shared techniques such as string obfuscation and direct syscalls.
MITRE Techniques
- [T1056.001] Keylogging â The campaign used clipboard hijacking and input capture-style behavior to deliver commands to victims (âwrites it to the victimâs clipboardâ).
- [T1027] Obfuscated Files or Information â Remus protected C2 configuration with ChaCha20 and used obfuscated scripts to hinder analysis (âprotect their embedded C2 configurationâ, âobfuscated commandsâ).
- [T1055] Process Injection â Remus targeted browser credentials via browser-process injection (âvia browser-process injectionâ).
- [T1115] Clipboard Data â The ClickFix chain wrote a malicious command into the clipboard for the victim to paste (âwrites it to the victimâs clipboardâ).
- [T1204.002] Malicious File â User Execution: Malicious File â Victims were lured into running cracked software and loader files (âcracked software luresâ, âcracked game installerâ).
- [T1036] Masquerading â Samples spoofed the Host header to appear as microsoft[.]com or github[.]com (âspoofing the Host header to microsoft[.]com or github[.]comâ).
- [T1071.001] Web Protocols â Remus registered and exfiltrated over HTTP/POST (âregisters with its C2 over HTTPâ, âexfiltrates via multipart POSTâ).
- [T1090] Proxy â The campaign used Cloudflare proxying on loader domains (âCloudflare proxyingâ).
- [T1105] Ingress Tool Transfer â Loader chains fetched shellcode and payloads from remote infrastructure (âfetches the final encrypted payloadâ, âretrieves a loader PE firstâ).
- [T1021.001] Remote Services: Remote Desktop Protocol â Not observed directly; no supported evidence in the article for RDP use.
- [T1106] Native API â Remus used direct syscall patterns and syscall abuse in loaders (âdirect syscall patternâ, âsyscall.Syscall execution transfer abuseâ).
- [T1140] Deobfuscate/Decode Files or Information â Samples decrypted embedded payloads and config at runtime (âdecrypts it at runtimeâ, âpython to decrypt the configurationâ).
- [T1218.005] System Binary Proxy Execution: Mshta â Not present in the article; omitted from operational assessment.
- [T1202] Indirect Command Execution â The ClickFix chain used PowerShell to execute payloads in memory (âdecrypted and executed entirely within the PowerShell processâs own memoryâ).
Indicators of Compromise
- [Domains ] C2, loader, and staging infrastructure â fightwa[.]biz, robinhuds[.]com, genuskox[.]biz, one-verif[.]lol
- [IPs ] observed C2 and delivery endpoints â 188.40.60[.]27, 84.21.189[.]150
- [URLs ] payload and blob retrieval locations â hxxp[:]//84.21.189[.]150:5000/rena.bin, hxxp[:]//31.77.168[.]180:5000/piva.exe
- [Files ] loader and payload artifacts â StartiqC.exe, StartiqC.rar, rena.bin, piva.exe
- [Hashes ] verified sample identifiers â d42595b695fc008ef2c56aabd8efd68e, 6ad5041f, b100823b, and other 1 hash
- [Network/Services ] C2 registration and blockchain lookup infrastructure â ethereum-rpc[.]publicnode[.]com, TCP 5902, genuskox[.]biz:4378
- [Directories ] execution artifacts left on disk â %LOCALAPPDATA%Info.exe, INetCacheIEpiva[1].exe