SLTT C2 Traffic Tied to Remus Malware Distribution Operation

SLTT C2 Traffic Tied to Remus Malware Distribution Operation
CIS CTI tracked Remus infostealer distribution from March to September 2026, showing how the MaaS operation uses browser-session theft, EtherHiding C2 rotation, and multiple delivery chains to spread the payload. The investigation tied Remus to Lumma Stealer lineage and highlighted activity involving ClickFix, PLYCHIP, DonutLoader, GoFlateLoader, LandUpdate808, and domains such as fightwa[.]biz, robinhuds[.]com, and genuskox[.]biz. #Remus #LummaStealer #EtherHiding #ClickFix #PLYCHIP #DonutLoader #GoFlateLoader #LandUpdate808

Keypoints

  • Remus infostealer distribution activity was observed across March through September 2026.
  • The malware operates under a MaaS affiliate model with tiered subscriptions and customized binaries for each affiliate.
  • Remus focuses on stealing authenticated browser sessions, cookies, credentials, and master keys to bypass MFA.
  • CIS CTI identified three main delivery chains: ClickFix with PLYCHIP, DonutLoader shellcode delivery, and cracked-software bundling with GoFlateLoader.
  • The operator can rotate C2 infrastructure through EtherHiding, which uses Ethereum smart contracts to fetch live endpoints.
  • Remus also expanded collection to AI clients such as Claude, Codex, OpenCode, Cursor, and Devin.
  • The campaign overlaps with Lumma Stealer lineage through the intermediate project Tenzor and shared techniques such as string obfuscation and direct syscalls.

MITRE Techniques

  • [T1056.001] Keylogging – The campaign used clipboard hijacking and input capture-style behavior to deliver commands to victims (‘writes it to the victim’s clipboard’).
  • [T1027] Obfuscated Files or Information – Remus protected C2 configuration with ChaCha20 and used obfuscated scripts to hinder analysis (‘protect their embedded C2 configuration’, ‘obfuscated commands’).
  • [T1055] Process Injection – Remus targeted browser credentials via browser-process injection (‘via browser-process injection’).
  • [T1115] Clipboard Data – The ClickFix chain wrote a malicious command into the clipboard for the victim to paste (‘writes it to the victim’s clipboard’).
  • [T1204.002] Malicious File – User Execution: Malicious File – Victims were lured into running cracked software and loader files (‘cracked software lures’, ‘cracked game installer’).
  • [T1036] Masquerading – Samples spoofed the Host header to appear as microsoft[.]com or github[.]com (‘spoofing the Host header to microsoft[.]com or github[.]com’).
  • [T1071.001] Web Protocols – Remus registered and exfiltrated over HTTP/POST (‘registers with its C2 over HTTP’, ‘exfiltrates via multipart POST’).
  • [T1090] Proxy – The campaign used Cloudflare proxying on loader domains (‘Cloudflare proxying’).
  • [T1105] Ingress Tool Transfer – Loader chains fetched shellcode and payloads from remote infrastructure (‘fetches the final encrypted payload’, ‘retrieves a loader PE first’).
  • [T1021.001] Remote Services: Remote Desktop Protocol – Not observed directly; no supported evidence in the article for RDP use.
  • [T1106] Native API – Remus used direct syscall patterns and syscall abuse in loaders (‘direct syscall pattern’, ‘syscall.Syscall execution transfer abuse’).
  • [T1140] Deobfuscate/Decode Files or Information – Samples decrypted embedded payloads and config at runtime (‘decrypts it at runtime’, ‘python to decrypt the configuration’).
  • [T1218.005] System Binary Proxy Execution: Mshta – Not present in the article; omitted from operational assessment.
  • [T1202] Indirect Command Execution – The ClickFix chain used PowerShell to execute payloads in memory (‘decrypted and executed entirely within the PowerShell process’s own memory’).

Indicators of Compromise

  • [Domains ] C2, loader, and staging infrastructure – fightwa[.]biz, robinhuds[.]com, genuskox[.]biz, one-verif[.]lol
  • [IPs ] observed C2 and delivery endpoints – 188.40.60[.]27, 84.21.189[.]150
  • [URLs ] payload and blob retrieval locations – hxxp[:]//84.21.189[.]150:5000/rena.bin, hxxp[:]//31.77.168[.]180:5000/piva.exe
  • [Files ] loader and payload artifacts – StartiqC.exe, StartiqC.rar, rena.bin, piva.exe
  • [Hashes ] verified sample identifiers – d42595b695fc008ef2c56aabd8efd68e, 6ad5041f, b100823b, and other 1 hash
  • [Network/Services ] C2 registration and blockchain lookup infrastructure – ethereum-rpc[.]publicnode[.]com, TCP 5902, genuskox[.]biz:4378
  • [Directories ] execution artifacts left on disk – %LOCALAPPDATA%Info.exe, INetCacheIEpiva[1].exe


Read more: https://www.cisecurity.org/insights/blog/sltt-c2-traffic-tied-to-remus-malware-distribution-operation