Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Unmasking The 64-bit Variant of the Infamous Lumma Stealer

buccstanor.pics

TLP:CLEAR
Active

Domain

Description

Gen Threat Labs has identified Remus, a new 64-bit infostealer attributed to the Lumma Stealer family, emerging after Lumma's takedown and the doxxing of its alleged core members. First campaigns date back to February 2026, with the malware switching from Steam/Telegram dead drop resolvers to EtherHiding and employing new anti-analysis checks. Remus shares multiple characteristics with Lumma including identical string obfuscation techniques, AntiVM checks, direct syscall/sysenter handling, indirect control flow obfuscation, and a unique Application-Bound Encryption bypass. The analysis details test builds labeled Tenzor from September 2025, representing a transitional step between Lumma and Remus. While maintaining Lumma's stealing arsenal for browser passwords, cookies, and cryptocurrency, Remus introduces blockchain-based C2 resolution via EtherHiding, additional anti-sandbox checks targeting analysis tool DLLs, and enhanced device fingerprinting capabilities.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Unmasking The 64-bit Variant of the Infamous Lumma Stealer
Pattern Type
STIX
Confidence
75%
Valid From
May 10, 2026 05:43
Total Sightings
0
Added
May 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of buccstanor.pics

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.