Briefing

Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution

security
by Sponsored by Flare ·

Patch: Deploy endpoint detection to flag REMUS signatures, block cookie and session theft, and enforce strict password‑manager access controls.

What to do now

Patch: Deploy endpoint detection to flag REMUS signatures, block cookie and session theft, and enforce strict password‑manager access controls.

Summary

REMUS, a new infostealer that emerged in early 2026, has evolved rapidly from a simple credential‑stealing tool into a full‑featured malware‑as‑a‑service platform. The operator’s underground posts show a compressed development cycle that introduced restore‑token functionality, expanded log handling, worker tracking, and statistics pages in March, followed by SOCKS5 proxy support, anti‑VM toggles, gaming‑platform targeting, and password‑manager collection in April. REMUS now actively collects IndexedDB data from 1Password, LastPass, and Bitwarden extensions, as well as cookies and authenticated session tokens, allowing attackers to bypass MFA and maintain persistent access. The operation emphasizes operational visibility, with worker nicknames, duplicate‑log filtering, and a 24/7 support promise, and claims a ~90 % delivery rate when paired with proper crypting and an intermediary server. Technical analysis confirms that REMUS shares anti‑VM checks, browser credential theft, and encryption‑bypass techniques with the Lumma stealer, but the underground data reveals a commercial mindset focused on session persistence and monetization. The shift from credential harvesting to session theft reflects a broader trend in the underground economy, where stolen cookies and authenticated sessions are increasingly valuable. REMUS’s evolution demonstrates how modern MaaS ecosystems resemble legitimate software businesses, with continuous development, bug fixes, and operational refinements. The campaign highlights the growing importance of authenticated sessions and browser‑side authentication artifacts for attackers.

Key changes

  • REMUS introduced restore‑token functionality and expanded log handling in March 2026.
  • Added SOCKS5 proxy support, anti‑VM toggles, gaming‑platform targeting, and password‑manager collection (IndexedDB for 1Password, LastPass, Bitwarden).
  • Shifted focus to authenticated session theft, token restoration, and proxy‑assisted session recovery.
  • Operated as a MaaS with continuous development, versioned updates, bug fixes, and operational visibility enhancements.
  • Achieved ~90 % delivery rate with proper crypting and an intermediary server.
  • Emphasized cookie collection, token handling, and browser sessions as core value.

Affects

enterprise internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting