MB-0d298a65db890328d0357b2fb39ea7352645a994a601f430c38450769635f957
high
📛 Threat Title
RemusStealer: file
Description
File type: exe. Size: 2205704 bytes. Tags: dropped-by-GCleaner, exe, F, MIX7.file, RemusStealer, signed. Reporter: Bitsight. First seen: 2026-08-04 21:22:42.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
d9c0bfb4053066384ee7484b4c2917f9
IOC database
- Type
- hash_imphash
- Value
d9c0bfb4053066384ee7484b4c2917f9- First seen
- Last seen
- Attached to this threat
- Appears in
- 6 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
0d298a65db890328d0357b2fb39ea7352645a994a601f430c38450769635f957
IOC database
- Type
- hash_sha256
- Value
0d298a65db890328d0357b2fb39ea7352645a994a601f430c38450769635f957- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- RemusStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
feb272114aba399e891d551603b195c4bce264c7
IOC database
- Type
- hash_sha1
- Value
feb272114aba399e891d551603b195c4bce264c7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
4264991601686145d9e14f36c1e7b3d9
IOC database
- Type
- hash_md5
- Value
4264991601686145d9e14f36c1e7b3d9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2205704 bytes. Tags: dropped-by-GCleaner, exe, F, MIX7.file, RemusStealer, signed. Reporter: Bitsight. First seen: 2026-08-04 21:22:42.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Gen, this is most likely the 64bit evolution of Lumma Stealer. It is capable of stealing stored browser passwords, cookies, cryptocurrency, and much more. It also uses EtherHiding to resolve C2s, replacing the traditional use of Steam and Telegram dead drop resolvers, and has additional anti-analysis checks.
-
web:malware-guide.com
Simple Steps To Eliminate Malicious Application Remus is a type of malware, or malicious software, designed to steal sensitive information from a victim's computer. It is similar to another malware called Lumma, but Remus is an updated and more advanced version. Both of these malware programs are known as "stealers" because their main job is In order to remove Remus Stealer, you should ...
-
web:radar.offseq.com
Detailed information about Remus Stealer - 64bit evolution of Lumma. Get real-time updates, technical details, and mitigation strategies.
-
web:socprime.com
Newer anti-analysis additions include sandbox DLL hash checks and a "honeypot" PST file presence test intended to detect analysis environments. Mitigation Block known Remus-related C2 IPs/domains at the perimeter and monitor for EtherHiding behavior, including unusual lookups or traffic patterns consistent with smart-contract-based C2 ...
-
web:techjacksolutions.com
Executive Summary Financially motivated operators are running a large-scale campaign using fake websites that impersonate trusted open-source security tools, Ghidra, dnSpy, and SpiderFoot, and rank them at the top of Google search results through SEO manipulation. Developers and security analysts who download from these sites receive credential-stealing malware (Remus Stealer), a ...
-
web:www.gendigital.com
Key points Gen Threat Labs has identified Remus, a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions. We also describe a previously undocumented Application-Bound ...
-
web:www.microsoft.com
Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...
-
web:www.pcrisk.com
My computer is infected with Remus stealer, should I format my storage device to get rid of it? This approach can fully eliminate Remus, but it will also delete all data and files stored on the device. Instead of resetting or formatting the system, it is generally recommended to first use a reliable security tool such as Combo Cleaner.
-
web:www.securitricks.com
Gen Threat Labs has identified Remus, a new 64-bit infostealer attributed to the Lumma Stealer family, emerging after Lumma's takedown and the doxxing of its alleged core members. First campaigns date back to February 2026, with the malware switching from Steam/Telegram dead drop resolvers to EtherHiding and employing new anti-analysis checks. Remus shares multiple characteristics with Lumma ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.