MB-e5ad4b3ede90666c09a53b703037503ea8c221ba9fa6648268e94c8fda87842c
high
📛 Threat Title
RemusStealer: loader.exe
Description
File type: exe. Size: 94669656 bytes. Tags: electron, exe, infostealer, RemusStealer, signed. Reporter: Alex_sev. First seen: 2026-09-24 17:48:41.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
b34f154ec913d2d2c435cbd644e91687
IOC database
- Type
- hash_imphash
- Value
b34f154ec913d2d2c435cbd644e91687- First seen
- Last seen
- Attached to this threat
- Appears in
- 169 threats
- Description
- imphash of URLhaus payload 6b10f4383fd8de21…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
e5ad4b3ede90666c09a53b703037503ea8c221ba9fa6648268e94c8fda87842c
IOC database
- Type
- hash_sha256
- Value
e5ad4b3ede90666c09a53b703037503ea8c221ba9fa6648268e94c8fda87842c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- RemusStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
282b7bcaa07840ab96a3c738af9538fdf6f4b24b
IOC database
- Type
- hash_sha1
- Value
282b7bcaa07840ab96a3c738af9538fdf6f4b24b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
69e9ab256f86433cb7e6890cc84eb784
IOC database
- Type
- hash_md5
- Value
69e9ab256f86433cb7e6890cc84eb784- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 94669656 bytes. Tags: electron, exe, infostealer, RemusStealer, signed. Reporter: Alex_sev. First seen: 2026-09-24 17:48:41.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:cybersecuritynews.com
Remus Windows stealer uses ClickFix attacks to steal passwords, wallet data, files, browser information, and AI tool credentials.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Gen, this is most likely the 64bit evolution of Lumma Stealer. It is capable of stealing stored browser passwords, cookies, cryptocurrency, and much more. It also uses EtherHiding to resolve C2s, replacing the traditional use of Steam and Telegram dead drop resolvers, and has additional anti-analysis checks.
-
web:malware-guide.com
Simple Steps To Eliminate Malicious Application Remus is a type of malware, or malicious software, designed to steal sensitive information from a victim's computer. It is similar to another malware called Lumma, but Remus is an updated and more advanced version. Both of these malware programs are known as "stealers" because their main job is In order to remove Remus Stealer, you should ...
-
web:securityarsenal.com
An unpatched proof-of-concept dubbed BigDiskBuster silently stops Microsoft Defender platform and signature updates by exhausting disk space. Here's how to detect and mitigate it before attackers weaponize it.
-
web:undercodetesting.com
This is not the final RemusStealer but a sophisticated loader. This loader employs a custom five-stage decryption routine to reflectively load the main RemusStealer payload directly into memory, making file-based detection difficult. Step‑by‑step guide explaining what this does and how to use it:
-
web:www.enigmasoftware.com
A newly identified infostealer known as REMUS has gained significant attention across the cybercrime ecosystem due to its rapid development pace, expanding feature set, and growing resemblance to a professional Malware-as-a-Service (MaaS) operation. Security researchers and malware analysts have already highlighted similarities between REMUS and the widely known Lumma Stealer, particularly in ...
-
web:www.gendigital.com
Key points Gen Threat Labs has identified Remus, a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions. We also describe a previously undocumented Application-Bound ...
-
web:www.microsoft.com
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...
-
web:www.pcrisk.com
What kind of malware is Remus? Remus is a stealer associated with Lumma. It shares similar capabilities, including the ability to steal browser passwords, cookies, and cryptocurrency wallet information. It is considered to be an evolution of Lumma (not a separate malware). Remus uses new techniques such as EtherHiding and improved anti-analysis checks. More about Remus Remus likely evolved ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.