SLTT C2 Traffic Tied to Remus Malware Distribution Operation
The Center for Internet Security® (CIS®) Cyber Threat Intelligence (CTI) team identified Remus infostealer distribution activity spanning March through September 2026.
Open-source reporting indicates Remus prioritizes stealing authenticated browser sessions to bypass multi-factor authentication (MFA). The operator distributes Remus through a Malware as a Service (MaaS) affiliate model, meaning each subscriber runs independent delivery infrastructure. Remus Pro and Enterprise tier subscribers can rotate command and control (C2) addresses via EtherHiding, a blockchain-based mechanism which updates C2 endpoints without registering new domains.
CIS CTI's investigation, supported by technical analysis from the CIS Cyber Incident Response Team (CIRT), identified three distinct Remus subscriber delivery chains using ClickFix and PLYCHIP staging, DonutLoader shellcode, and GoFlateLoader bundled in cracked software lures.
Remus Overview
Through Remus operator-published forum posts and cybersecurity company Gen Digital's code analysis, CIS CTI confirmed Remus traces its lineage to Lumma Stealer through an intermediate project called Tenzor. Remus shares Lumma's string obfuscation technique and direct syscall pattern.
According to a post by the developer on the Exploit threat actor forum, as reported by Flashpoint, Remus’s MaaS model offers subscriptions to independent criminal operators at three price tiers: $250, $500, and $1,000 per month. Each subscriber, called an "affiliate," uses a campaign builder within the operator panel to generate a customized Remus binary with unique identifiers tied to their operation.
Packet captures (pcap) from sandbox reports revealed Remus communicates with its C2 server via an encrypted channel. Remus registers with its C2 over HTTP on non-standard ports then exfiltrates via multipart POST. The POST body carries fields including tag=, hwid=, and access_token= that identify the victim build, device, and affiliate campaign.
CIS CTI observed several samples across all three delivery chains spoofing the Host header to microsoft[.]com or github[.]com while the connection reaches the real C2 IP, which is consistent with a "host replacement during analysis" feature the developer documented in a June 19 changelog post. Open-source reporting from Flashpoint, aachum, and Check Point Research indicates Remus targets Chromium and Firefox browser credentials, cookies, and master keys via browser-process injection, clipboard content, screenshots, file-system search, and session tokens from an extension target list of up to 332 password manager and cryptocurrency wallet extensions.
On July 29, the Remus developer published an announcement on Exploit forum indicating the infostealer had expanded its collection capabilities to target artificial intelligence (AI) clients including Claude, Codex, OpenCode, Cursor, and Devin.
EtherHiding C2
Remus supports two C2 resolution mechanisms in sequence when enabled at the Pro and Enterprise tiers. According to Gen Digital and aachum, the first is a hardcoded domain list followed by an EtherHiding blockchain resolver.
The EtherHiding mechanism queries a smart contract on the Ethereum blockchain to retrieve the live C2 domain and port. CIS CTI observed a Remus payload briefly communicating with ethereum-rpc[.]publicnode[.]com, in which it obtained the C2 domain, fightwa[.]biz, and proceeded to communicate with the domain over TCP port 5902. Because the address is stored on the blockchain rather than on registrar-controlled infrastructure, notes Flashpoint, operators can rotate C2 endpoints with a single contract transaction.
Defenders can block access to domains that feature Ethereum smart contract-related services if there is no business need for them, but blockchains are intended to be publicly accessible, and threat actors will likely find workarounds to continue to leverage this technique if defenders start blocking them.
Since its emergence in 2023, open-source reporting from Chainalysis documents EtherHiding adoption across more than a dozen malware families and five major blockchains as of mid 2026, spanning both cybercriminal and state-linked actors.
Remus Payload Configuration Encryption
Remus payloads protect their embedded C2 configuration with the ChaCha20 encryption algorithm, which inhibits static analysis tools such as string searches or scans from reading the data directly. CIS CTI verified the encryption across two independent payloads. In each, a 32-byte key, an 8-byte nonce, and the encrypted configuration are stored as static plaintext in .rdata. Using python to decrypt the configuration yields a table of three C2 URLs the payload attempts to contact in sequence. The operator embeds the key in the binary so the payload can decrypt its configuration without external input. This means a defender with a captured sample can recover the key, decrypt the configuration, and extract active C2 addresses without detonating the sample in a sandbox.
Remus Delivery Chains
The three Remus delivery chains CIS CTI identified distribute the Remus payload through ClickFix with PLYCHIP staging, DonutLoader shellcode staging, and GoFlateLoader bundled in cracked software. The team's investigation examined these three based on Multi-State Information Sharing and Analysis Center® (MS-ISAC®) member activity and subsequent pivots, but this list is non-exhaustive, as open-source reporting from Palo Alto Networks indicates additional delivery chains across Remus affiliates.
Chain 1: ClickFix Delivery
CIS CTI identified a ClickFix command, which included a URL pointing to one-verif[.]lol. Targeted pivoting on one-verif[.]lol and domains with matching registration records yielded several PowerShell samples. Static decoding, pcap, memory dump, and Windows XML Event Log (EVTX) analysis of those samples confirmed the Remus payload was decrypted and executed entirely within the PowerShell process's own memory.
Pivoting on the ClickFix clipboard-hijack JavaScript file injected into the reported compromised site surfaced a web-injection network of 82 domains serving behaviorally similar files. CIS CTI analyzed the source code across a subset of these domains and determined they are likely associated with LandUpdate808, a multi-tenant traffic distribution system (TDS) also tracked as TAG-124 and KongTuke which serves multiple malware families.
Static analysis of the JavaScript hosted on the likely LandUpdate808 domains revealed it collects device and environment attributes to fingerprint the victim and filter out sandbox environments and automated scanners, including checks for WebDriver, Selenium, PhantomJS, and Nightmare.js. It also requires the browser to complete a computational challenge, likely to filter out automated scanners.
The fingerprint, alongside the user agent, referrer, and ad-campaign tracking parameters, is submitted to the server. If the server approves, the script builds a full-screen overlay iframe presenting a fake verification prompt and injects an inline script that fetches a base64-encoded remote command, decodes it, and writes it to the victim's clipboard. If the clipboard API is unavailable or the write is rejected, the script uses a hidden text area and a legacy copy command.
The command written to the clipboard directs victims to one-verif[.]lol, which CIS CTI discovered is one of a cluster of 45 loader domains sharing the "PDR Ltd." registrar, Cloudflare proxying, and anonymous registrant contacts.
WHOIS records for these domains resolved to three recurring registrant personas active in sequential windows between June 8 and July 27, 2026. The rotating personas likely point to a single threat actor or group cycling identities on a one- to four-week cadence.
CIS CTI has not directly observed the execution of the copied command. However, based on shared registration records across the loader domain cluster and associated PLYCHIP scripts, the team assesses with moderate confidence that the clipboard command directs victims through PLYCHIP-hosted loader domains to the Remus payload. Google Threat Intelligence (GTI), accessible through VirusTotal, defines PLYCHIP as a multi-stage PowerShell-based downloader and screening tool. CIS CTI pivoted on files scanned by VirusTotal that communicate with domains in this cluster and observed numerous PowerShell scripts tagged as PLYCHIP.
PLYCHIP Pre-Filter and Screening
PLYCHIP samples observed in this investigation profile and filter victims' machines by checking Workgroup or domain membership and installed antivirus. In some variants, they also check running processes for analysis tools before reporting findings to staging infrastructure and receiving the final payload.
The domain membership check consists of branching logic based on Workgroup or domain-joined machines. If the victim's machine is enrolled in an Active Directory environment, PLYCHIP collects the domain name and domain computer objects and multiplies the count by three. CIS CTI could not reproduce the domain-joined logic in a controlled environment, only the Workgroup logic.
Pcap analysis revealed samples reported findings to a server and received at least two obfuscated commands in response. The obfuscated commands satisfied two purposes:
- Fetching an obfuscated loader script from the server. The loader also contains a XOR key.
- Relaying an “s=” value to a PHP script at a separate
.topdomain. There were no observed responses from.topdomains across six PLYCHIP samples, indicating this communication is for reporting information and does not inhibit victims from receiving the Remus payload. Notably, some samples received inactive commands alongside active ones.149d0bdareceived four commands, two of which were inactive and contained calls to.topdomains observed across other PLYCHIP samples.
After fulfilling the screening and staging steps, the PLYCHIP script fetches the final encrypted payload. The payload returned to Workgroup machines exhibited the Remus C2 registration sequence with protocol fields matching confirmed Remus samples.
CIS CTI did not observe the EtherHiding technique in these examples likely because initial C2 communications succeeded.

ClickFix Chain 1 with PLYCHIP Screening
Chain 2: Donut Shellcode Delivering Remus in Memory
Using Chain 1 C2 domain infrastructure as a pivot point, CIS CTI identified a distinct mechanism called DonutLoader delivering Remus samples.
Accoring to TheWover, DonutLoader is an open-source tool that packages executables as shellcode and runs them directly in process memory without writing to disk. CIS CIRT attributed the samples to DonutLoader through VirusTotal and Tria.ge[a] tagging, a byte-for-byte match of the loader stub across all four blobs, and successful decryption using Volexity's open-source donut-decryptor tool, with additional insight provided by ANY.RUN.
CIS CTI identified four distinct shellcode blobs across this chain, rena.bin, apris.bin, sem.bin, and umvbr.bin, delivering Remus through two sequence types. Each blob carries an encrypted Remus PE, decrypts it at runtime, and maps it into memory with the PE header zeroed.
- In the first sequence type, a loader already on the victim’s computer fetches one of three blobs directly from a bare IP on TCP/5000 (e.g.
hxxp[:]//84.21.189[.]150:5000/rena.bin) and maps the decrypted payload into memory. The loader process then registers to Remus C2 infrastructure (e.g.http[:]//josegza[.]biz:8521) using the full Remus protocol. - In the second, a downloader (e.g.
ffa78f3d) already on the victim’s computer retrieves a loader PE first (e.g.hxxp[:]//31.77.168[.]180:5000/piva.exe), writes it to disk as%LOCALAPPDATA%\Info.exe, executes it, and the loader follows the same fetch (e.g.hxxp[:]//31.77.168[.]180:5000/umvbr.bin), decrypt, and map pattern.
In both types, the loader fetches the blob via URLDownloadToCacheFileW, which leaves a copy of the shellcode container in the INetCache path. The loader then deletes the container within seconds. The Remus executable inside remains encrypted in that file and is never written to disk.
In the second sequence type, the loader left %LOCALAPPDATA%\Info.exe and its own cached copy at INetCache\IE\<8-random-chars>\piva[1].exe in place. Both were still present at the end of every observed run.
Every observed loader detonation deleted Prefetch entries and wiped %TEMP%, but CIS CTI was able to capture this behavior through sandbox recording.
Chain 3: Cracked Software Bundling
An Albert Network Monitoring and Management alert on an additional Remus domain, robinhuds[.]com, prompted CIS CTI to pivot on that domain's registration records. This action surfaced genuskox[.]biz, another Remus C2 domain.
Analysis recovered a cracked game installer, StartiqC.exe (b100823b), distributed inside StartiqC.rar (6ad5041f). CIS CIRT verified the sample was a 754,518,668-byte Go 1.25.10 binary, of which 751,578,252 bytes (99.6%) were overlay padding appended after the last PE section. To accomplish this, the threat actors append data beyond the PE’s default section table with null or random bytes to artificially inflate the size of the file, also known as a "PE overlay."
The sample beaconed to genuskox[.]biz:4378 (188.40.60[.]27) and completed the full Remus C2 registration sequence across 81 plaintext HTTP POSTs. Its import hash, d42595b695fc008ef2c56aabd8efd68e, matched four samples CIS CTI verified as GoFlateLoader. Three of those samples were identified independently, and the fourth was tagged as GoFlateLoader in open-source reporting. The sample also carried the syscall.Syscall execution transfer abuse by pointing to the Remus payload’s entry point, which aligns with Gen Digital's reporting of GoFlateLoader behavior.
Join the MS-ISAC to Strengthen Your Defenses
The CIS CTI team recommends U.S. State, Local, Tribal, and Territorial (SLTT) government organizations join the MS-ISAC, a community dedicated to the Collective Cyber Defense of U.S. SLTTs. MS-ISAC members received early reporting on this malware campaign, including over 100 indicators of compromise (IOCs) disseminated through our Indicator Sharing Program. Additionally, members can take advantage of proactive web security through the Malicious Domain Blocking and Reporting (MDBR) service. Finally, the CIS CTI team provided membership with a more detailed report on this campaign, including IOCs and recommendations. This information is intended to provide actionable threat intelligence that directly supports proactive Collective Cyber Defense in the U.S. SLTT community along with informed decision making.
Ready to help your organization stay safe against threats like Remus?
[a] Tria.ge is Recorded Future's malware analysis sandbox available at https://tria.ge.
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.