s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932704 high

📛 Threat Title

Remus: URL that is used for botnet Command&control (C&C) http://vgfeden.shop:7728/webhooks

Category: Remus Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 07:18:39 UTC. Reporter: Myrtus0x0. Tags: Remus.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://vgfeden.shop:7728/webhooks VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovL3ZnZmVkZW4uc2hvcDo3NzI4L3dlYmhvb2tz
UrlVoid 1 / 36

IOC database

Type
url
Value
http://vgfeden.shop:7728/webhooks
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Remus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovL3ZnZmVkZW4uc2hvcDo3NzI4L3dlYmhvb2tz

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 07:18:39 UTC. Reporter: Myrtus0x0. Tags: Remus.

Remediations (10)

  • web:any.run

    Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

  • web:cyberpress.org

    The campaign stands out because Remus does not rely only on a hardcoded command-and-control (C2) domain. Instead, it queries an Ethereum smart contract to obtain the current C2 address, using a technique known as EtherHiding.

  • web:cybersecuritynews.com

    Remus Hides Its Command Server on Ethereum At the heart of this campaign is the decision to hide Remus's command server information inside an Ethereum smart contract rather than hard‑coding it in the malware.

  • web:portal.vyprsec.ai

    A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.

  • web:threatfox.abuse.ch

    ThreatFox IOC Database You are viewing the ThreatFox database entry for url http ://vgfeden.shop:7728/categories. Database Entry

  • web:threatfox.abuse.ch

    You are viewing the ThreatFox database entry for url http ://vgfeden.shop:7728/comments.

  • web:threatfox.abuse.ch

    You are viewing the ThreatFox database entry for url http://vgfeden.shop:7728/webhooks .

  • web:urlhaus.abuse.ch

    Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.

  • web:www.gendigital.com

    Key points Gen Threat Labs has identified Remus , a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.