Gen Threat Labs has identified Remus, a new 64-bit infostealer attributed to the Lumma Stealer family, emerging after Lumma's takedown and the doxxing of its alleged core members. First campaigns date back to February 2026, with the malware switching from Steam/Telegram dead drop resolvers to EtherHiding and employing new anti-analysis checks. Remus shares multiple characteristics with Lumma including identical string obfuscation techniques, AntiVM checks, direct syscall/sysenter handling, indirect control flow obfuscation, and a unique Application-Bound Encryption bypass. The analysis details test builds labeled Tenzor from September 2025, representing a transitional step between Lumma and Remus. While maintaining Lumma's stealing arsenal for browser passwords, cookies, and cryptocurrency, Remus introduces blockchain-based C2 resolution via EtherHiding, additional anti-sandbox checks targeting analysis tool DLLs, and enhanced device fingerprinting capabilities.
Executive Summary
Lumma Stealer has emerged with a new variant, Remus, following the takedown of its parent group. This infostealer targets financial information using advanced obfuscation and blockchain-based C2 infrastructure.
Goals & Targeting
The actor likely aims to steal financial credentials for monetization. While no specific sectors or countries are targeted explicitly, the use of advanced techniques suggests targeting individuals across various sectors using digital assets.
Enhanced Description
Remus is a sophisticated 64-bit infostealer linked to the Lumma Stealer family. Emerging post-takedown in February 2026, it employs enhanced anti-analysis techniques and blockchain C2 via EtherHiding. Inherited from Lumma, it features string obfuscation, AntiVM checks, syscall handling, indirect control flow obfuscation, and encryption bypasses. Remus targets browser data, crypto assets, and cookie information. Its transitional phase, test builds labeled 'Tenzor,' indicate a strategic evolution aimed at evading detection while maintaining its primary mission of information theft.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Campaigns observed since February 2026 focus on infostealing via Remus, utilizing blockchain C2 and anti-analysis measures. Notable for targeting individuals across sectors, particularly crypto users.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in technical details from Gen Threat Labs analysis. Strategic intent and victimology are less clear, limiting confidence in long-term patterns.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
131
IOCs
0
Observed Data
0
Tactics