Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lumma stealer

Description

Gen Threat Labs has identified Remus, a new 64-bit infostealer attributed to the Lumma Stealer family, emerging after Lumma's takedown and the doxxing of its alleged core members. First campaigns date back to February 2026, with the malware switching from Steam/Telegram dead drop resolvers to EtherHiding and employing new anti-analysis checks. Remus shares multiple characteristics with Lumma including identical string obfuscation techniques, AntiVM checks, direct syscall/sysenter handling, indirect control flow obfuscation, and a unique Application-Bound Encryption bypass. The analysis details test builds labeled Tenzor from September 2025, representing a transitional step between Lumma and Remus. While maintaining Lumma's stealing arsenal for browser passwords, cookies, and cryptocurrency, Remus introduces blockchain-based C2 resolution via EtherHiding, additional anti-sandbox checks targeting analysis tool DLLs, and enhanced device fingerprinting capabilities.

AI Analysis

· 1 week ago

Executive Summary

Lumma Stealer has emerged with a new variant, Remus, following the takedown of its parent group. This infostealer targets financial information using advanced obfuscation and blockchain-based C2 infrastructure.

Goals & Targeting

The actor likely aims to steal financial credentials for monetization. While no specific sectors or countries are targeted explicitly, the use of advanced techniques suggests targeting individuals across various sectors using digital assets.

Enhanced Description

Remus is a sophisticated 64-bit infostealer linked to the Lumma Stealer family. Emerging post-takedown in February 2026, it employs enhanced anti-analysis techniques and blockchain C2 via EtherHiding. Inherited from Lumma, it features string obfuscation, AntiVM checks, syscall handling, indirect control flow obfuscation, and encryption bypasses. Remus targets browser data, crypto assets, and cookie information. Its transitional phase, test builds labeled 'Tenzor,' indicate a strategic evolution aimed at evading detection while maintaining its primary mission of information theft.

Key Capabilities

  • 64-bit infostealing malware
  • String obfuscation techniques
  • AntiVM checks
  • Direct syscall/sysenter handling
  • Indirect control flow obfuscation
  • Unique Application-Bound Encryption bypass
  • Blockchain-based C2 resolution via EtherHiding
  • Enhanced anti-sandbox and anti-analysis checks
  • Device fingerprinting capabilities

MITRE ATT&CK Tactics

Defense Evasion
Credential Access
Exfiltration

ATT&CK Techniques

T1057 - Anti-Debugging
T1055 - Process Injection
T1566.001 - Account Access Removal

Software / Tooling

Remus Infostealer
Custom malware family Lumma Stealer

Campaigns & Victims

Campaigns observed since February 2026 focus on infostealing via Remus, utilizing blockchain C2 and anti-analysis measures. Notable for targeting individuals across sectors, particularly crypto users.

IOC Patterns

  • Infostealing malware activity
  • Blockchain-based C2 infrastructure
  • Enhanced anti-analysis techniques

Recommended Actions

  • Implement robust endpoint detection solutions
  • Monitor network traffic for blockchain-exiting behaviors
  • Update anti-VM and AntiDebugging measures
  • Conduct regular user training on phishing and safe browsing practices

Suggested Tags

Malware Family
Infostealer
Financial Espionage

Confidence Assessment

High confidence in technical details from Gen Threat Labs analysis. Strategic intent and victimology are less clear, limiting confidence in long-term patterns.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

131

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Critical Infrastructure
Backdoor / C2
Malware Family
Infostealer
Financial Espionage

Details

Type
Unknown
Confidence
55%
Added
May 10, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.