s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-0d298a65db890328d0357b2fb39ea7352645a994a601f430c38450769635f957 high

📛 Threat Title

RemusStealer: file

Category: RemusStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2205704 bytes. Tags: dropped-by-GCleaner, exe, F, MIX7.file, RemusStealer, signed. Reporter: Bitsight. First seen: 2026-08-04 21:22:42.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash d9c0bfb4053066384ee7484b4c2917f9

IOC database

Type
hash_imphash
Value
d9c0bfb4053066384ee7484b4c2917f9
First seen
Last seen
Attached to this threat
Appears in
6 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 0d298a65db890328d0357b2fb39ea7352645a994a601f430c38450769635f957

IOC database

Type
hash_sha256
Value
0d298a65db890328d0357b2fb39ea7352645a994a601f430c38450769635f957
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
RemusStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 feb272114aba399e891d551603b195c4bce264c7

IOC database

Type
hash_sha1
Value
feb272114aba399e891d551603b195c4bce264c7
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 4264991601686145d9e14f36c1e7b3d9

IOC database

Type
hash_md5
Value
4264991601686145d9e14f36c1e7b3d9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2205704 bytes. Tags: dropped-by-GCleaner, exe, F, MIX7.file, RemusStealer, signed. Reporter: Bitsight. First seen: 2026-08-04 21:22:42.

Remediations (10)

  • web:any.run

    Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Gen, this is most likely the 64bit evolution of Lumma Stealer. It is capable of stealing stored browser passwords, cookies, cryptocurrency, and much more. It also uses EtherHiding to resolve C2s, replacing the traditional use of Steam and Telegram dead drop resolvers, and has additional anti-analysis checks.

  • web:malware-guide.com

    Simple Steps To Eliminate Malicious Application Remus is a type of malware, or malicious software, designed to steal sensitive information from a victim's computer. It is similar to another malware called Lumma, but Remus is an updated and more advanced version. Both of these malware programs are known as "stealers" because their main job is In order to remove Remus Stealer, you should ...

  • web:radar.offseq.com

    Detailed information about Remus Stealer - 64bit evolution of Lumma. Get real-time updates, technical details, and mitigation strategies.

  • web:socprime.com

    Newer anti-analysis additions include sandbox DLL hash checks and a "honeypot" PST file presence test intended to detect analysis environments. Mitigation Block known Remus-related C2 IPs/domains at the perimeter and monitor for EtherHiding behavior, including unusual lookups or traffic patterns consistent with smart-contract-based C2 ...

  • web:techjacksolutions.com

    Executive Summary Financially motivated operators are running a large-scale campaign using fake websites that impersonate trusted open-source security tools, Ghidra, dnSpy, and SpiderFoot, and rank them at the top of Google search results through SEO manipulation. Developers and security analysts who download from these sites receive credential-stealing malware (Remus Stealer), a ...

  • web:www.gendigital.com

    Key points Gen Threat Labs has identified Remus, a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions. We also describe a previously undocumented Application-Bound ...

  • web:www.microsoft.com

    Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts. You can also visit our advanced ...

  • web:www.pcrisk.com

    My computer is infected with Remus stealer, should I format my storage device to get rid of it? This approach can fully eliminate Remus, but it will also delete all data and files stored on the device. Instead of resetting or formatting the system, it is generally recommended to first use a reliable security tool such as Combo Cleaner.

  • web:www.securitricks.com

    Gen Threat Labs has identified Remus, a new 64-bit infostealer attributed to the Lumma Stealer family, emerging after Lumma's takedown and the doxxing of its alleged core members. First campaigns date back to February 2026, with the malware switching from Steam/Telegram dead drop resolvers to EtherHiding and employing new anti-analysis checks. Remus shares multiple characteristics with Lumma ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.