RemusStealer is a malware-as-a-service (MaaS) program with multiple similarities to LummaStealer. LummaStealer is a notorious information stealer active since at least 2022 and has been covered in a previous Binary Defense blog post regarding ClickFix initial access methods, which can be found here.
Noted similarities between RemusStealer and LummaStealer include anti-virtual machine checks and credential theft tactics, alongside the method of bypass in Application-Bound Encryption (ABE). ABE policies are used to prevent unauthorized access to the encryption keys used to secure data in web browsers.
In contrast, one key difference between LummaStealer and RemusStealer in recent campaigns is that, instead of utilizing Steam or Telegram as a dead drop resolver, RemusStealer is observed to employ Ethereum smart contracts to facilitate C2 communications.
EtherHiding is a tactic leveraged by some threat actors to masquerade malicious communications through smart contracts. Malicious code is embedded into a smart contract on a public blockchain, such as Ethereum, to essentially turn the blockchain into a C2 server. Dynamic analysis within the Binary Defense malware lab revealed that recent samples of RemusStealer will attempt to reach out to eth[.]llamarpc[.]com, which is associated with Ethereum.
Initial static analysis of RemusStealer revealed that the payload is written in Go, with functionality consistent of discovery tactics via the following:
-GetSystemInfo
-GetSystemDirectoryA
When executed, the payload performed system discovery via the following:
-SELECT * FROM AntiVirusProduct
-SELECT * FROM Win32_VideoController
-SELECT * FROM Win32_OperatingSystem
These commands gather information regarding the compromised system’s operating system, detailed information on hardware specifications, settings and status information in relation to graphics/display adapters, and the current installed antivirus product.
After this, an outbound connection was established to IP address 144.91.74[.]47 over port 6473, followed by a POST request. Packet analysis revealed an initial "check-in" POST request with an access token pointing to the host shivlpf[.]shop over port 6473. Multiple samples were analyzed in the Binary Defense malware lab, with each sample attempting to reach out to a domain ending in either [.]shop or [.]biz.

RemusStealer is observed to employ the use of hidden/alternative desktops as a means to evade detection on the compromised machine by the victim. The usual primary interactive desktop is labelled WinSta0\\Default, with observed sandbox process labels containing the string “sbox”. Typically, attackers will focus on a user session that can be assigned various Windows Station objects, where each Station object can have multiple desktop objects. These can then be used nefariously by attackers to hide malicious activity while the user continues to interact with their system.
In the case of RemusStealer, msedge.exe is launched on a non-primary window station/desktop by the payload.

Microsoft Edge is then launched an additional two times, for a total of three processes with the same alterative desktop information. msedge.exe then opens the hosts configuration file, then proceeds to launch an additional two msedge child processes.

RemusStealer then accesses the following Microsoft Edge credential files:
-Web Data (~\Users\<REDACTED>\AppData\Local\Microsoft\Edge\User Data\Default\Web Data)
-Login Data (~\Users\<REDACTED>\AppData\Local\Microsoft\Edge\User Data\Default\Login Data)
After gathering credentials from Microsoft Edge, RemusStealer then moved to the Brave browser, performing the same cycle of execution on a non-primary window/desktop, enumeration of the host configuration file, then additional child launches followed by collection of Brave credential files. The cycle repeats until all sensitive data is gathered.
As more variants move towards smart contracts/blockchain activity to hide it’s true malicious nature, detection efforts must focus on:
Binary Defense’s Threat Research team develops and refines behavioral detections and hunting queries against rapidly changing variants like this, then applies them within our own SOC. Threat Hunting is included with Binary Defense MDR.
Remus: Unmasking The 64-bit Variant of the Infamous Lumma Stealer, GenDigital, https://www.gendigital.com/blog/insights/research/remus-64bit-variant-of-lumma-stealer#key-points
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution, BleepingComputer, https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/
Detect Suspicious Processes Running on Hidden Desktops, Microsoft, https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/detect-suspicious-processes-running-on-hidden-desktops/4072322
ApplicationBoundEncryptionEnabled, MicrosoftLearn, https://learn.microsoft.com/en-us/deployedge/microsoft-edge-policies/applicationboundencryptionenabled
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains, Google Mandiant,
https://cloud.google.com/blog/topics/threat-intelligence/dprk-adopts-etherhiding