Remus is a Windows information stealer that has garnered attention for its ability to conceal itself before stealing data. The malware surfaced on underground marketplaces in March 2026 and is designed to collect browser information, cryptocurrency wallet data, passwords, and files from compromised computers. The investigation found that the malware targets data from 21 browsers and 16 cold wallets, as well as collecting a wide variety of Mozilla extensions, including those used for two-factor authentication.
Remus functions (Source – SpyCloud) The approach mirrors tactics used in recent EDR evasion campaigns, where attackers seek to obscure visibility before moving on to credential theft or other malicious activities.
Users who encounter fake CAPTCHA malware delivery should understand the crucial takeaway: a web verification check should never necessitate pasting a command into Windows. Indicators of compromise (IoCs): - Ethereum smart contract 0x999941b74F6bbc921D5174A5b29911562cd2D7CF: Active DomainStorage dead-drop contract used to retrieve live command-and-control infrastructure - Ethereum smart contract 0xF6896c4ddD2B821d5d2B3c18459Acd9b5Ec1cE21: Unused DomainStorage contract associated with the same owner - Ethereum address 0xBeCFC3F9EB36E6Ec0E54f7A6627DA7EF648f8F01: Owner address for the identified contracts - RPC node hxxps://ethereum-rpc[.]publicnode[. ]com: Ethereum RPC endpoint contacted to query the dead-drop contract - Command-and-control server fightwa[.
]biz:5902: Live C2 infrastructure returned through the contract resolver - File name honey@pot[. ]com.pst: Sandbox-detection filename searched in Outlook storage directories Securely integrate threat intelligence from platforms like MISP, VirusTotal, or your SIEM.











