s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932575 high

📛 Threat Title

Remus: Domain that is used for botnet Command&control (C&C) bdducts.click

Category: Remus Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 100. First seen: 2026-09-25 06:28:03 UTC. Reporter: Dgomez22. Tags: fake-crack, mediafire, Remus, stealer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain bdducts.click UrlVoid 3 / 36

IOC database

Type
domain
Value
bdducts.click
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Remus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 100. First seen: 2026-09-25 06:28:03 UTC. Reporter: Dgomez22. Tags: fake-crack, mediafire, Remus, stealer.

Remediations (10)

  • web:cybersecuritynews.com

    Remus Windows stealer uses ClickFix attacks to steal passwords, wallet data, files, browser information, and AI tool credentials.

  • web:flashpoint.io

    Although Remus bears remarkable similarities to Lumma, its main differences lie in its C2 beaconing. Before performing main stealer functionality, Remus will beacon out to its C2 infrastructure. It will attempt to resolve several domain:port combinations via POST requests, and attempt a final connection to find the C2 server using EtherHiding.

  • web:spycloud.com

    SpyCloud analysts reverse engineer Remus , a new infostealer using etherhiding and syscall evasion to steal wallets, passwords, and AI credentials.

  • web:threatfox.abuse.ch

    You are viewing the ThreatFox database entry for url http://poagint.click:8592/posts.

  • web:undercodenews.com

    The most innovative aspect of this campaign is Remus' use of Ethereum blockchain technology. Instead of embedding a fixed command-and-control server, the malware performs an eth_call JSON-RPC request to a hardcoded Ethereum smart contract. The smart contract returns an encoded response containing the current active C2 server.

  • web:undercodenews.com

    Remus represents a significant leap forward in malware sophistication, merging tried-and-tested credential theft mechanics with next-generation evasion. By adopting EtherHiding and blockchain-based C2 discovery, Remus demonstrates an understanding of decentralized infrastructure, making it far more resilient to takedowns than previous malware ...

  • web:www.gendigital.com

    Key points Gen Threat Labs has identified Remus , a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions.

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.spamhaus.org

    Networks hosting botnet C&Cs : Same players, same problems With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening?

  • web:www.spamhaus.org

    Botnet Threat Update July to December 2025 Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.