Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Oracle Solaris CVE-2024-21013 Flaw Lets Attackers Remotely Control Servers
August 6, 2026
Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider
August 6, 2026
Critical Jenkins CVE-2024-28973 Lets Attackers Run Code on Controllers
August 6, 2026
Home/Threats/Remus Malware Uses Ethereum Blockchain to Steal Browser Data
Threats

Remus Malware Uses Ethereum Blockchain to Steal Browser Data

Key Takeaways Remus is a new information stealer targeting Windows systems, primarily through fake cracked software sites. It extracts passwords, cookies, and cryptocurrency wallet data from popular...

Emy Elsamnoudy
Emy Elsamnoudy
August 6, 2026 5 Min Read
3 0

Key Takeaways

  • Remus is a new information stealer targeting Windows systems, primarily through fake cracked software sites.
  • It extracts passwords, cookies, and cryptocurrency wallet data from popular web browsers.
  • A key innovation is its use of the Ethereum blockchain to dynamically retrieve Command and Control (C2) server addresses, making traditional blocking methods less effective.
  • The malware employs SEO poisoning and targets users seeking pirated software, often delivering multiple infostealers simultaneously.

A sophisticated new information-stealing malware, dubbed Remus, has emerged, actively compromising Windows systems to pilfer sensitive data from web browsers. This stealthy threat is engineered to extract saved passwords, session cookies, and cryptocurrency wallet information, posing a significant risk to user privacy and financial security.

Table Of Content

  • Key Takeaways
  • Remus Hides Its Command Server on Ethereum
  • What You Should Do

The current distribution campaign for Remus heavily relies on deceptive cracked software websites. These sites are meticulously designed to mimic legitimate download portals, luring unsuspecting users searching for free productivity tools and games. Once downloaded and executed, Remus prioritizes the exfiltration of data stored within browser vaults and online account credentials, transforming routine web activity into a critical security vulnerability.

Researchers at Unit42 said in a report that this particular wave of attacks is characterized by a combination of aggressive SEO poisoning and the use of Turkish-language warez storefronts. File names containing terms like “İndir” (download) and “Türkçe” (Turkish) are specifically crafted to attract victims seeking pirated software. The infrastructure supporting these downloads is not exclusive to Remus; it serves as a shared platform for various info-stealers, indicating a broader malware-as-a-service operation rather than a singular, isolated campaign. Unit42’s analysis further revealed that the operators behind this campaign frequently rotate domains and IP addresses to maintain persistence and evade detection efforts.

Upon successful execution, Remus injects itself into running Chromium-based browsers via remote threads. This allows it to directly access browser vaults, bypassing disk encryption to harvest saved passwords, session cookies, and other confidential data. Beyond browsers, the malware extends its reach to password managers, FTP clients, clipboard contents, screenshots, and enterprise email storage files, providing attackers with a comprehensive snapshot of a victim’s digital footprint within minutes.

Remus Hides Its Command Server on Ethereum

A distinctive feature of the Remus campaign is its innovative use of the Ethereum blockchain for Command and Control (C2) communication. Instead of relying on hard-coded server addresses, Remus performs an on-chain lookup to a specific Ethereum smart contract (address 0x999941b74F6bbc921D5174A5b29911562cd2D7CF) via a JSON-RPC request to a public Ethereum endpoint like ethereum-rpc[.]publicnode[.]com. The decoded response provides a live C2 URL, which then serves as the destination for stolen data. This data is exfiltrated via HTTP POST requests, disguised as benign diagnostic or telemetry logs, to domains such as fimmora[.]surf, zelpx[.]garden, and tzpx[.]courses. This dynamic C2 mechanism, similar to techniques seen in EtherHiding and other blockchain-backed campaigns, significantly complicates defense efforts that rely on static domain blocking, as the smart contract remains constant while the underlying infrastructure can rapidly shift.

Remus leverages the encryption mechanisms of Chromium-based browsers to its advantage. It extracts OS-level encrypted master keys from local state files, then uses these to retrieve AES keys and application-data protection master keys. This allows the malware to decrypt saved passwords and other credentials offline, meaning attackers can unlock stolen database files at a later time without needing further access to the victim’s machine. The combination of browser data theft, cryptocurrency extension compromise, password manager access, FTP credential exfiltration, and email storage file access means a single infection can lead to a widespread compromise of personal, gaming, and enterprise accounts.

The distribution network for Remus is not a single malicious site but a network of open directories and warez stores, such as dwn[.]metaforgechain4[.]lol, which simultaneously host Remus alongside other info-stealers like Lumma and Vidar. These sites feature catalogs of fake cracked software and games, with archives specifically named to attract Turkish users. The frequent updates to these directories indicate an actively maintained and shared distribution-as-a-service operation, with sibling domains exhibiting similar naming conventions, bulk registration patterns, and privacy-protected WHOIS records. This model aligns with a broader trend of attackers utilizing trusted-looking download channels and dynamic backend infrastructure to evade detection.

What You Should Do

  • Avoid Pirated Software: Never download or install cracked software, games, or productivity tools from unofficial sources. These are primary vectors for malware like Remus.
  • Keep Software Updated: Ensure your operating system, web browsers (especially Chromium-based ones), and password managers are always updated to their latest versions to patch known vulnerabilities.
  • Implement Strong Endpoint Security: Utilize reputable antivirus and endpoint detection and response (EDR) solutions capable of detecting suspicious process injection into browser processes and unusual outbound HTTP traffic, particularly to newly registered domains or non-standard ports.
  • Monitor Network Traffic: Watch for HTTP POST requests that spoof Host headers and send data to unusual ports. Network monitoring tools should also flag any abnormal connections to blockchain RPC endpoints from user devices.
  • Strengthen Authentication: Enable multi-factor authentication (MFA) on all critical online accounts. This adds a crucial layer of security even if passwords are compromised.
  • Educate Users: Implement regular cybersecurity awareness training within organizations, emphasizing the dangers of unofficial software downloads and phishing attempts.
  • Block Known Indicators: Configure firewalls and intrusion prevention systems to block access to the identified malicious domains, IP addresses, and smart contract addresses associated with the Remus campaign.

Indicators of Compromise (IoCs):-

Type Indicator Description
Domain dwn[.]metaforgechain4[.]lol Malicious warez storefront hosting Remus and other infostealers
Domain fimmora[.]surf Remus C2 domain resolving to 165.227.123[.]79:6504
IP:Port 165.227.123[.]79:6504 C2 node receiving Remus HTTP POST exfiltration traffic
Domain zelpx[.]garden Remus C2 domain resolving to 77.42.90[.]175:9895
IP:Port 77.42.90[.]175:9895 C2 node used in the observed Remus campaign
Domain tzpx[.]courses Remus C2 domain resolving to 167.99.78[.]100:4437
IP:Port 167.99.78[.]100:4437 Additional C2 node for Remus exfiltration
Domain fightwa[.]biz C2 domain associated with the wider Remus infrastructure
IP:Port 148.230.76[.]66:5902 C2 IP:Port linked to fightwa[.]biz
Domain chalx[.]live C2 domain linked to Remus activity
IP:Port 147.135.84[.]14:5902 C2 IP:Port associated with chalx[.]live
IP 143.244.141[.]187 Historical third C2 node used by zelpx[.]garden
Domain fasea[.]top Co‑hosted C2 sibling domain on shared Remus infrastructure
Domain noevara[.]shop Co‑hosted C2 sibling domain on shared Remus infrastructure
Domain dikdiy[.]xyz Co‑hosted C2 sibling domain on shared Remus infrastructure
Domain fluokq[.]xyz Co‑hosted C2 sibling domain on shared Remus infrastructure
Domain approe[.]shop Co‑hosted C2 sibling domain on shared Remus infrastructure
Domain dolmaq[.]shop Co‑hosted C2 sibling domain on shared Remus infrastructure
Domain dreaub[.]top Co‑hosted C2 sibling domain sharing infrastructure with Remus
Domain pivotq[.]top Co‑hosted C2 sibling domain sharing infrastructure with Remus
Contract 0x999941b74F6bbc921D5174A5b29911562cd2D7CF Ethereum smart contract queried to resolve Remus C2 URL
Domain ethereum-rpc[.]publicnode[.]com Public Ethereum RPC endpoint used by Remus to query C2 contract
SHA256 f52809d57d816cf9ea7e95de64df46fcc1cf62d3da972c167497935b5eca74d7 Remus infostealer sample from current campaign
SHA256 51bfb2f390653647b087d789ef1559c3fdf220c565a909f1eee4d593893420dd Remus infostealer sample from current campaign
SHA256 205fc66381b8e254508d40c693a1314c9fc2b94b8023b29483803c8b0e449c4d Remus infostealer sample from current campaign
SHA256 da7935affcec91c317acf98b52eca551f2501b29ad502749e4c084492142c6eb Remus infostealer sample from current campaign
SHA256 ece6e9395edb8935c993a2945ac196a614149d65f10212e912e4654981646e37 Remus infostealer sample from current campaign
SHA256 b29391ba505af508f2110f54f73b203e2710b8b6c8a8717005e5c7a4050630e1 Remus infostealer sample from current campaign
SHA256 231123d03fa985bdb4edbcc45fafc8f4fb93f692b00f6f37df81435cd0ff1c7b Remus infostealer sample from current campaign
SHA256 35392a9849d7e9dfb4ee700a16700a94883fde859d57fdd891631bdbc6a75db0 Remus infostealer sample from current campaign
SHA256 6aa279fe9991405963ddf7ab18116fcde85190c2639b830791fe903d90697dec Remus infostealer sample from current campaign
SHA256 7b092a35e70113f5165a653135cb3a7ca29312ceb0b4a874c160473d30830a60 Remus infostealer sample from current campaign
SHA256 80965fa878946421e5778044fcb16bc523206eb8f3853c0f833e9dbb87fe24f1 Remus infostealer sample from current campaign
SHA256 57c1b9fe23cd8220f39383c2ab5b392e8f1416cbf75e2668fc6426294abb818f Remus infostealer sample from current campaign
SHA256 a84ab5bc2462fa6f673f22f59e759de458d4e561763af3be0bc3397564272347 Remus infostealer sample from current campaign
SHA256 e008c4e82cff39aa0f4c040944f8deeb80b06c50aab558e8b84e20c8ee453418 Remus infostealer sample from current campaign
SHA256 44d8e760012d6f08e91fd59176e59a3e13326f8079cdcc6e3a43b30f040769b6 Remus infostealer sample from current campaign
SHA256 d9da446bbb8adcb72c5c086705d58a8dad9d9268606e86568b893d122384b5b3 Remus infostealer sample from current campaign
SHA256 28c30dc88160f1fc44a5c11976f9de8da06be3c996d50ef76b0dbd032da210b6 Remus infostealer sample from current campaign
SHA256 1a398687d1f626e71c3beec3b0bda9589415babbcdae6171293c097d3103472e Remus infostealer sample from current campaign
SHA256 fb5a654149e5bdb09b1453fa7679e32826e81abbaa0114ca02b13be6408a5ee3 Remus infostealer sample from current campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

OWASP Releases Top 10 for Securing Generative AI LLM Applications

Next Post

Linux Kernel Bridge Vulnerability Lets Attackers Crash Systems, Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OWASP Releases Top 10 for Securing Generative AI LLM Applications
August 6, 2026
OpenAI Agents Uncover Critical Zero-Day Vulnerability
August 6, 2026
Meta AI Model Exploited to Hack Third-Party System
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us