TF-1932575
high
📛 Threat Title
Remus: Domain that is used for botnet Command&control (C&C) bdducts.click
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 100. First seen: 2026-09-25 06:28:03 UTC. Reporter: Dgomez22. Tags: fake-crack, mediafire, Remus, stealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
bdducts.click
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
bdducts.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Remus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 100. First seen: 2026-09-25 06:28:03 UTC. Reporter: Dgomez22. Tags: fake-crack, mediafire, Remus, stealer.
Remediations (10)
-
web:cybersecuritynews.com
Remus Windows stealer uses ClickFix attacks to steal passwords, wallet data, files, browser information, and AI tool credentials.
-
web:flashpoint.io
Although Remus bears remarkable similarities to Lumma, its main differences lie in its C2 beaconing. Before performing main stealer functionality, Remus will beacon out to its C2 infrastructure. It will attempt to resolve several domain:port combinations via POST requests, and attempt a final connection to find the C2 server using EtherHiding.
-
web:spycloud.com
SpyCloud analysts reverse engineer Remus , a new infostealer using etherhiding and syscall evasion to steal wallets, passwords, and AI credentials.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http://poagint.click:8592/posts.
-
web:undercodenews.com
The most innovative aspect of this campaign is Remus' use of Ethereum blockchain technology. Instead of embedding a fixed command-and-control server, the malware performs an eth_call JSON-RPC request to a hardcoded Ethereum smart contract. The smart contract returns an encoded response containing the current active C2 server.
-
web:undercodenews.com
Remus represents a significant leap forward in malware sophistication, merging tried-and-tested credential theft mechanics with next-generation evasion. By adopting EtherHiding and blockchain-based C2 discovery, Remus demonstrates an understanding of decentralized infrastructure, making it far more resilient to takedowns than previous malware ...
-
web:www.gendigital.com
Key points Gen Threat Labs has identified Remus , a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions.
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.spamhaus.org
Networks hosting botnet C&Cs : Same players, same problems With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening?
-
web:www.spamhaus.org
Botnet Threat Update July to December 2025 Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.