Remus Malware Uses Ethereum Blockchain to Steal Browser Data
Key Takeaways Remus is a new information stealer targeting Windows systems, primarily through fake cracked software sites. It extracts passwords, cookies, and cryptocurrency wallet data from popular...
Key Takeaways
- Remus is a new information stealer targeting Windows systems, primarily through fake cracked software sites.
- It extracts passwords, cookies, and cryptocurrency wallet data from popular web browsers.
- A key innovation is its use of the Ethereum blockchain to dynamically retrieve Command and Control (C2) server addresses, making traditional blocking methods less effective.
- The malware employs SEO poisoning and targets users seeking pirated software, often delivering multiple infostealers simultaneously.
A sophisticated new information-stealing malware, dubbed Remus, has emerged, actively compromising Windows systems to pilfer sensitive data from web browsers. This stealthy threat is engineered to extract saved passwords, session cookies, and cryptocurrency wallet information, posing a significant risk to user privacy and financial security.
Table Of Content
The current distribution campaign for Remus heavily relies on deceptive cracked software websites. These sites are meticulously designed to mimic legitimate download portals, luring unsuspecting users searching for free productivity tools and games. Once downloaded and executed, Remus prioritizes the exfiltration of data stored within browser vaults and online account credentials, transforming routine web activity into a critical security vulnerability.
Researchers at Unit42 said in a report that this particular wave of attacks is characterized by a combination of aggressive SEO poisoning and the use of Turkish-language warez storefronts. File names containing terms like “İndir” (download) and “Türkçe” (Turkish) are specifically crafted to attract victims seeking pirated software. The infrastructure supporting these downloads is not exclusive to Remus; it serves as a shared platform for various info-stealers, indicating a broader malware-as-a-service operation rather than a singular, isolated campaign. Unit42’s analysis further revealed that the operators behind this campaign frequently rotate domains and IP addresses to maintain persistence and evade detection efforts.
Upon successful execution, Remus injects itself into running Chromium-based browsers via remote threads. This allows it to directly access browser vaults, bypassing disk encryption to harvest saved passwords, session cookies, and other confidential data. Beyond browsers, the malware extends its reach to password managers, FTP clients, clipboard contents, screenshots, and enterprise email storage files, providing attackers with a comprehensive snapshot of a victim’s digital footprint within minutes.
Remus Hides Its Command Server on Ethereum
A distinctive feature of the Remus campaign is its innovative use of the Ethereum blockchain for Command and Control (C2) communication. Instead of relying on hard-coded server addresses, Remus performs an on-chain lookup to a specific Ethereum smart contract (address 0x999941b74F6bbc921D5174A5b29911562cd2D7CF) via a JSON-RPC request to a public Ethereum endpoint like ethereum-rpc[.]publicnode[.]com. The decoded response provides a live C2 URL, which then serves as the destination for stolen data. This data is exfiltrated via HTTP POST requests, disguised as benign diagnostic or telemetry logs, to domains such as fimmora[.]surf, zelpx[.]garden, and tzpx[.]courses. This dynamic C2 mechanism, similar to techniques seen in EtherHiding and other blockchain-backed campaigns, significantly complicates defense efforts that rely on static domain blocking, as the smart contract remains constant while the underlying infrastructure can rapidly shift.
Remus leverages the encryption mechanisms of Chromium-based browsers to its advantage. It extracts OS-level encrypted master keys from local state files, then uses these to retrieve AES keys and application-data protection master keys. This allows the malware to decrypt saved passwords and other credentials offline, meaning attackers can unlock stolen database files at a later time without needing further access to the victim’s machine. The combination of browser data theft, cryptocurrency extension compromise, password manager access, FTP credential exfiltration, and email storage file access means a single infection can lead to a widespread compromise of personal, gaming, and enterprise accounts.
The distribution network for Remus is not a single malicious site but a network of open directories and warez stores, such as dwn[.]metaforgechain4[.]lol, which simultaneously host Remus alongside other info-stealers like Lumma and Vidar. These sites feature catalogs of fake cracked software and games, with archives specifically named to attract Turkish users. The frequent updates to these directories indicate an actively maintained and shared distribution-as-a-service operation, with sibling domains exhibiting similar naming conventions, bulk registration patterns, and privacy-protected WHOIS records. This model aligns with a broader trend of attackers utilizing trusted-looking download channels and dynamic backend infrastructure to evade detection.
What You Should Do
- Avoid Pirated Software: Never download or install cracked software, games, or productivity tools from unofficial sources. These are primary vectors for malware like Remus.
- Keep Software Updated: Ensure your operating system, web browsers (especially Chromium-based ones), and password managers are always updated to their latest versions to patch known vulnerabilities.
- Implement Strong Endpoint Security: Utilize reputable antivirus and endpoint detection and response (EDR) solutions capable of detecting suspicious process injection into browser processes and unusual outbound HTTP traffic, particularly to newly registered domains or non-standard ports.
- Monitor Network Traffic: Watch for HTTP POST requests that spoof Host headers and send data to unusual ports. Network monitoring tools should also flag any abnormal connections to blockchain RPC endpoints from user devices.
- Strengthen Authentication: Enable multi-factor authentication (MFA) on all critical online accounts. This adds a crucial layer of security even if passwords are compromised.
- Educate Users: Implement regular cybersecurity awareness training within organizations, emphasizing the dangers of unofficial software downloads and phishing attempts.
- Block Known Indicators: Configure firewalls and intrusion prevention systems to block access to the identified malicious domains, IP addresses, and smart contract addresses associated with the Remus campaign.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | dwn[.]metaforgechain4[.]lol | Malicious warez storefront hosting Remus and other infostealers |
| Domain | fimmora[.]surf | Remus C2 domain resolving to 165.227.123[.]79:6504 |
| IP:Port | 165.227.123[.]79:6504 | C2 node receiving Remus HTTP POST exfiltration traffic |
| Domain | zelpx[.]garden | Remus C2 domain resolving to 77.42.90[.]175:9895 |
| IP:Port | 77.42.90[.]175:9895 | C2 node used in the observed Remus campaign |
| Domain | tzpx[.]courses | Remus C2 domain resolving to 167.99.78[.]100:4437 |
| IP:Port | 167.99.78[.]100:4437 | Additional C2 node for Remus exfiltration |
| Domain | fightwa[.]biz | C2 domain associated with the wider Remus infrastructure |
| IP:Port | 148.230.76[.]66:5902 | C2 IP:Port linked to fightwa[.]biz |
| Domain | chalx[.]live | C2 domain linked to Remus activity |
| IP:Port | 147.135.84[.]14:5902 | C2 IP:Port associated with chalx[.]live |
| IP | 143.244.141[.]187 | Historical third C2 node used by zelpx[.]garden |
| Domain | fasea[.]top | Co‑hosted C2 sibling domain on shared Remus infrastructure |
| Domain | noevara[.]shop | Co‑hosted C2 sibling domain on shared Remus infrastructure |
| Domain | dikdiy[.]xyz | Co‑hosted C2 sibling domain on shared Remus infrastructure |
| Domain | fluokq[.]xyz | Co‑hosted C2 sibling domain on shared Remus infrastructure |
| Domain | approe[.]shop | Co‑hosted C2 sibling domain on shared Remus infrastructure |
| Domain | dolmaq[.]shop | Co‑hosted C2 sibling domain on shared Remus infrastructure |
| Domain | dreaub[.]top | Co‑hosted C2 sibling domain sharing infrastructure with Remus |
| Domain | pivotq[.]top | Co‑hosted C2 sibling domain sharing infrastructure with Remus |
| Contract | 0x999941b74F6bbc921D5174A5b29911562cd2D7CF | Ethereum smart contract queried to resolve Remus C2 URL |
| Domain | ethereum-rpc[.]publicnode[.]com | Public Ethereum RPC endpoint used by Remus to query C2 contract |
| SHA256 | f52809d57d816cf9ea7e95de64df46fcc1cf62d3da972c167497935b5eca74d7 | Remus infostealer sample from current campaign |
| SHA256 | 51bfb2f390653647b087d789ef1559c3fdf220c565a909f1eee4d593893420dd | Remus infostealer sample from current campaign |
| SHA256 | 205fc66381b8e254508d40c693a1314c9fc2b94b8023b29483803c8b0e449c4d | Remus infostealer sample from current campaign |
| SHA256 | da7935affcec91c317acf98b52eca551f2501b29ad502749e4c084492142c6eb | Remus infostealer sample from current campaign |
| SHA256 | ece6e9395edb8935c993a2945ac196a614149d65f10212e912e4654981646e37 | Remus infostealer sample from current campaign |
| SHA256 | b29391ba505af508f2110f54f73b203e2710b8b6c8a8717005e5c7a4050630e1 | Remus infostealer sample from current campaign |
| SHA256 | 231123d03fa985bdb4edbcc45fafc8f4fb93f692b00f6f37df81435cd0ff1c7b | Remus infostealer sample from current campaign |
| SHA256 | 35392a9849d7e9dfb4ee700a16700a94883fde859d57fdd891631bdbc6a75db0 | Remus infostealer sample from current campaign |
| SHA256 | 6aa279fe9991405963ddf7ab18116fcde85190c2639b830791fe903d90697dec | Remus infostealer sample from current campaign |
| SHA256 | 7b092a35e70113f5165a653135cb3a7ca29312ceb0b4a874c160473d30830a60 | Remus infostealer sample from current campaign |
| SHA256 | 80965fa878946421e5778044fcb16bc523206eb8f3853c0f833e9dbb87fe24f1 | Remus infostealer sample from current campaign |
| SHA256 | 57c1b9fe23cd8220f39383c2ab5b392e8f1416cbf75e2668fc6426294abb818f | Remus infostealer sample from current campaign |
| SHA256 | a84ab5bc2462fa6f673f22f59e759de458d4e561763af3be0bc3397564272347 | Remus infostealer sample from current campaign |
| SHA256 | e008c4e82cff39aa0f4c040944f8deeb80b06c50aab558e8b84e20c8ee453418 | Remus infostealer sample from current campaign |
| SHA256 | 44d8e760012d6f08e91fd59176e59a3e13326f8079cdcc6e3a43b30f040769b6 | Remus infostealer sample from current campaign |
| SHA256 | d9da446bbb8adcb72c5c086705d58a8dad9d9268606e86568b893d122384b5b3 | Remus infostealer sample from current campaign |
| SHA256 | 28c30dc88160f1fc44a5c11976f9de8da06be3c996d50ef76b0dbd032da210b6 | Remus infostealer sample from current campaign |
| SHA256 | 1a398687d1f626e71c3beec3b0bda9589415babbcdae6171293c097d3103472e | Remus infostealer sample from current campaign |
| SHA256 | fb5a654149e5bdb09b1453fa7679e32826e81abbaa0114ca02b13be6408a5ee3 | Remus infostealer sample from current campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.