Remus

First seen
2023-09-15 00:00:00
Malware type
credential-stealer, spyware
Last IoC activity
2026-07-22 02:41:14
Profile updated
2026-07-07 15:10:28

Targeted industries: financial-services technology-and-telecommunications

Context

According to Gen, this is most likely the 64bit evolution of Lumma Stealer. It is capable of stealing stored browser passwords, cookies, cryptocurrency, and much more. It also uses EtherHiding to resolve C2s, replacing the traditional use of Steam and Telegram dead drop resolvers, and has additional anti-analysis checks.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Remus_Auto (yara-rule)

Reports & references

  • gendigital.com — Remus 64Bit Variant Of Lumma Stealer (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Remus (report)

External references