{"id":26172,"date":"2026-09-21T15:12:59","date_gmt":"2026-09-21T23:12:59","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/infostealers-highlight-malware-as-a-service-trend\/"},"modified":"2026-09-21T15:12:59","modified_gmt":"2026-09-21T23:12:59","slug":"infostealers-highlight-malware-as-a-service-trend","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/infostealers-highlight-malware-as-a-service-trend\/","title":{"rendered":"Infostealers highlight malware-as-a-service trend"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>Attackers are leveraging infostealer malware-as-a-service (MaaS) for a variety of attacks, with malware of this nature showing up regularly in a variety of campaign types. ReversingLabs found several specific infostealers being used recently: AuraStealer, a very actively updated and maintained stealer with recently improved anti-analysis features, ACRStealer, a long standing malware family that has fallen in and out of use, and RemusStealer, a new potential variant on the infamous LummaStealer.\u00a0<\/p>\n<p>The samples covered were active in July through August of 2026. Here are the top infostealer MaaS trends, and the families that ReversingLabs has been researching. The goal is to provide readers with important knowledge of these threats, how they manifest, and what they are capable of \u2014 all of which is vital to know in the current threat landscape.\u00a0\u00a0<\/p>\n<p><strong>[ Get the report:\u00a0<\/strong><a href=\"https:\/\/www.reversinglabs.com\/clickfix\"><strong>Copy, Paste, Compromise: The Tale of ClickFix<\/strong><\/a><strong>\u00a0|\u00a0<\/strong><a href=\"https:\/\/www.reversinglabs.com\/events\/anatomy-of-a-clickfix-attack\"><strong>See the webinar<\/strong><\/a><strong>\u00a0]<\/strong><\/p>\n<h2 id=\"maas-lowers-the-bar-for-attackers\">MaaS lowers the bar for attackers<\/h2>\n<p>Malware-as-a-service (MaaS) is becoming increasingly important in the security landscape. It lowers the barrier of entry for attackers, giving anyone access to malware without requiring coding knowledge. The MaaS market functions like any other market does, where the best products rise to the top. Vendors compete with each other to make the best products and grow their businesses. To engage in this massive market, potential customers can purchase subscriptions to the service, lifetime licenses, or join affiliate programs. Affiliate programs are common with ransomware-as-a-service, where the malware producer takes a cut of the earnings, and their customers, the ones doing the ransomware attack, take home the rest. The types of MaaS offered vary, with any type of malware being offered somewhere for a fee. Infostealers are especially popular, and are what this blog focuses on.\u00a0<\/p>\n<p>Infostealers do exactly what their name implies. Once installed, they take information from the device and exfiltrate it to the attacker. Common targets for infostealers include credentials, personal information, crypto wallet information, and session tokens. More specialized targets may include documents on the machine, clipboard data, recordings, browser cookies, or applications data. Since infostealers can exfiltrate a variety of things, attackers are able to leverage them in whatever way best suits their goals. These goals may be leaking documents with important corporate information, finding data to be used for blackmail, or compromising the logins for critical accounts. Any of these options could be disastrous for individuals or businesses. Whatever data the infostealer may be targeting, it is not information one would want to be revealed to threat actors.<\/p>\n<p>Another important feature of infostealers, especially the popular ones operating as MaaS, is their stealth and evasion. Some infostealers, such as <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/05\/21\/lumma-stealer-breaking-down-the-delivery-techniques-and-capabilities-of-a-prolific-infostealer\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">LummaStealer<\/span><\/a>, use techniques like <a href=\"https:\/\/blog.qualys.com\/vulnerabilities-threat-research\/2024\/10\/20\/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">process hollowing and process injection<\/span><\/a>. These techniques involve putting malicious code into an existing, trusted process, avoiding detection. Users on the device will not be able to detect infostealer activity easily, without knowing what to look for. Many infostealers have basic anti-analysis functionality, can detect antivirus, sandboxing, or use of VMs, and will terminate themselves if signs point to them being analyzed. AuraStealer, which will be discussed later, gives the user a prompt before continuing, which is likely meant to combat automated analysis. <\/p>\n<div class=\"rich-media_container__AH6jG media-block_mediaBlock__nZBDJ\" data-position=\"center\" data-restrict=\"true\" data-size=\"fill\">\n<div class=\"rich-media_media__trppT\"><template id=\"P:e\"><\/template><\/p>\n<div class=\"rich-media_overlay__LSRfe\"><svg aria-hidden=\"true\" class=\"lucide lucide-expand\" fill=\"none\" height=\"24\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" viewbox=\"0 0 24 24\" width=\"24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"m15 15 6 6\"><\/path><path d=\"m15 9 6-6\"><\/path><path d=\"M21 16v5h-5\"><\/path><path d=\"M21 8V3h-5\"><\/path><path d=\"M3 16v5h5\"><\/path><path d=\"m3 21 6-6\"><\/path><path d=\"M3 8V3h5\"><\/path><path d=\"M9 9 3 3\"><\/path><\/svg><\/div>\n<\/div>\n<\/div>\n<p><em>Figure 1, Screenshot of prompt box asking user to enter a randomized string (pxDpRf) to continue.<\/em><\/p>\n<p>Infostealers can delete themselves when finished, or will delete themselves upon detection of analysis tools and environments.\u00a0<\/p>\n<p>During the past few months, the threat research team at ReversingLabs has been investigating and reporting on various infostealers. Focus was put on families with significant recent activity, and researchers delved specifically into features of active strains. The following is a summary of the research into three specific families, AuraStealer, ACRStealer\/Amatera, and Remus Stealer.<\/p>\n<h2 id=\"a-closer-look-at-key-infostealers\">A closer look at key infostealers<\/h2>\n<p>This trio of infostealers was specifically selected due to the recency of development and amount of use. ReversingLabs databases show that between June 1st and August 18th, AuraStealer had 26 samples submitted, ACRStealer had 397 (with an additional 81 for the related Amatera family) and Remus Stealer was the most prevalent with 606. Each of these counts are for unique executable samples that were submitted for the first time during the time frame.<\/p>\n<div class=\"rich-media_container__AH6jG media-block_mediaBlock__nZBDJ\" data-position=\"center\" data-restrict=\"true\" data-size=\"fill\">\n<div class=\"rich-media_media__trppT\"><template id=\"P:f\"><\/template><\/p>\n<div class=\"rich-media_overlay__LSRfe\"><svg aria-hidden=\"true\" class=\"lucide lucide-expand\" fill=\"none\" height=\"24\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" viewbox=\"0 0 24 24\" width=\"24\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"m15 15 6 6\"><\/path><path d=\"m15 9 6-6\"><\/path><path d=\"M21 16v5h-5\"><\/path><path d=\"M21 8V3h-5\"><\/path><path d=\"M3 16v5h5\"><\/path><path d=\"m3 21 6-6\"><\/path><path d=\"M3 8V3h5\"><\/path><path d=\"M9 9 3 3\"><\/path><\/svg><\/div>\n<\/div>\n<\/div>\n<p><em>Figure 2, A graph visualizing malware activity timeline for RemusStealer (red), AuraStealer (pink), ACRStealer (cyan), from June 1 to August 20 (Generated by Spectra Intelligence MCP).<\/em><\/p>\n<p>AuraStealer and Remus Stealer are also newer families, having existed for less than a year, and don\u2019t have as much data about them. The three are known for their ability to gather credentials from browsers and crypto wallets. All three are also tied to CIS countries and Russian language hacking forms, although there was no evidence found of direct relationships between the authors of these strains. They\u2019re used in a variety of social engineering schemes, showing the vast array of potential attackers using these services.\u00a0<\/p>\n<h3>AuraStealer\u00a0<\/h3>\n<p>AuraStealer is a relatively new player, emerging in July of 2025. It has gained significant momentum since. It is comparable to other infostealers, and <a href=\"http:\/\/x.com\/KrakenLabs_Team\/status\/1952302052928803182\"><span style=\"text-decoration:underline\">while it doesn\u2019t directly rip off any code<\/span><\/a>, it functions similarly to its direct competitors. It seems to be positioning itself to overtake the niches of other popular infostealers, like its most direct competitor and comparison point, LummaStealer. In fact, many <a href=\"https:\/\/foresiet.com\/blog\/aura-stealer-malware-analysis\/\"><span style=\"text-decoration:underline\">LummaStealer detections flag AuraStealer incorrectly,<\/span><\/a> at least initially. It operated as a subscription model, with basic and premium tiers, which are charged on a monthly or yearly basis.<\/p>\n<p>In practice, AuraStealer is used in a variety of attacks. Popular distribution methods leverage <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/defeating-aurastealer-obfuscation\"><span style=\"text-decoration:underline\">ClickFix<\/span><\/a> and malicious <a href=\"https:\/\/www.reversinglabs.com\/blog\/social-media-attacks-phishing\"><span style=\"text-decoration:underline\">short form videos<\/span><\/a>. Researchers discovered that AuraStealer had a major transformation in <a href=\"https:\/\/x.com\/GenThreatLabs\/status\/2056313248778002689\"><span style=\"text-decoration:underline\">summer of 2026<\/span><\/a> and this change brought virtualization. These virtualized files were directly observed by researchers at ReversingLabs. Virtualization is a technique that involves running custom commands through a virtual machine, which obfuscates and makes it harder to analyze. This change also immensely increased the filesize, bringing it from 500-700KB to 10MB.<\/p>\n<h3>ACRStealer (a.k.a. Amatera)<\/h3>\n<p>ACRStealer is an interesting case. It\u2019s been around for a while, <a href=\"https:\/\/www.stormshield.com\/news\/acridrain-stealer\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">starting out initially in 2018<\/span><\/a>. From there, it acted as a low level infostealer, not earning much success. In 2022, they rebranded and significantly upgraded the malware. It went on for two years, but in the middle of 2024, the <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/amatera-stealer-rebranded-acr-stealer-improved-evasion-sophistication\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">maintainers announced an indefinite hiatus<\/span><\/a>. This hiatus would involve the continuation of ongoing subscriptions, but halted the process of onboarding any new affiliates. A few months after this announcement, a new malware emerged, labeling itself as Amatera. A specific <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/amatera-stealer-rebranded-acr-stealer-improved-evasion-sophistication\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">management portal for Amatera was found<\/span><\/a>, and the samples associated with the panel and the Amatera name were very similar to ACRStealer. Despite the distinction in name, the two families are very similar, and it is difficult to discern what differentiates the two. Both families are in use to this day.\u00a0<\/p>\n<h3>Remus Stealer<\/h3>\n<p>Remus Stealer is the newest MaaS out of the three, having started at the very beginning of 2026. The <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/remus-64bit-variant-of-lumma-stealer\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">first signs of Remus<\/span><\/a> were in January and February, but researchers quickly caught onto it. What makes it compelling is the fact it seems to be a <a href=\"https:\/\/flashpoint.io\/blog\/remus-stealer-a-new-not-so-new-infostealer\/\"><span style=\"text-decoration:underline\">64-bit variant<\/span><\/a> of one of the most notorious infostealers: LummaStealer. LummaStealer is a flagship infostealer MaaS, maintaining prevalence even after a government raid of its infrastructure and the doxing of some of its key players. This comparison is drawn because Remus borrows a lot of Lumma\u2019s traits, such as <a href=\"https:\/\/flashpoint.io\/blog\/remus-stealer-a-new-not-so-new-infostealer\/\"><span style=\"text-decoration:underline\">handling of string obfuscation<\/span><\/a>, approach to application bound <a href=\"https:\/\/any.run\/malware-trends\/remus\/\"><span style=\"text-decoration:underline\">encryption (ABE) override<\/span><\/a>, and <a href=\"https:\/\/flashpoint.io\/blog\/remus-stealer-a-new-not-so-new-infostealer\/\"><span style=\"text-decoration:underline\">design of control panels<\/span><\/a>. <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/remus-64bit-variant-of-lumma-stealer\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">Remus is unique<\/span><\/a> for utilizing <a href=\"https:\/\/www.stormshield.com\/news\/cti-etherhiding-blockchain-technology\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">Etherhiding<\/span><\/a> as a C2 communication method, a trait which Lumma does not have. Etherhiding uses Ethereum smart contracts to communicate their C2 domains, which is harder to detect, trace and block. The name \u201cRemus\u201d is derived from log identification strings in the code, and Lumma samples utilize a similar nomenclature with their own logs.\u00a0<\/p>\n<p>Reports emphasize Remus\u2019s use in malvertising, SEO-poisoning and search redirection. It is also regularly used in ClickFix, fake reaCAPCTHA, and fake downloads. <a href=\"https:\/\/any.run\/malware-trends\/remus\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">One particular campaign<\/span><\/a> involved Traffic Distribution System (TDS) to make fake, malicious websites reach the top of Google search results for software related terms. These webpages would redirect into a Remus payload. Frequent organizational targets of Remus include healthcare, financial, government, MSPs, and tech, but it is also used in campaigns targeting individuals, especially through gaming communities. Currently, multiple loaders (Ameday, Gcleaner and OffLoader) are dropping Remus, and these samples utilize VMProtect or a Go-based delivery stage. <\/p>\n<h2 id=\"what-threat-hunters-should-look-out-for\">What threat hunters should look out for<\/h2>\n<p>These families are delivered in a variety of ways. Being aware of potential vectors is a crucial step in staying safe. Social engineering is the typical means of getting MaaS onto victim devices. ClickFix and <a href=\"https:\/\/www.reversinglabs.com\/blog\/clickfix-attacks-your-trust\"><span style=\"text-decoration:underline\">ClearFake<\/span><\/a> are two popular methods attackers use to get victims to install malware. <a href=\"https:\/\/www.reversinglabs.com\/blog\/clickfix-yara-rule\"><span style=\"text-decoration:underline\">ClickFix is a social engineering technique<\/span><\/a> designed to get a potential victim to run malicious commands on their own device. This typically occurs through malicious tech advice or fake reCAPTCHA verification. This technique is increasingly being seen on <a href=\"https:\/\/www.reversinglabs.com\/blog\/social-media-attacks-phishing\"><span style=\"text-decoration:underline\">social media videos<\/span><\/a>. ClearFake is a related technique, and has been consistently <a href=\"https:\/\/redcanary.com\/blog\/threat-intelligence\/intelligence-insights-june-2026\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">topping threat charts<\/span><\/a> as something to look out for. <\/p>\n<p>Leveraging <a href=\"https:\/\/www.darktrace.com\/blog\/clearfake-from-fake-captchas-to-blockchain-driven-payload-retrieval\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">Javascript<\/span><\/a>,\u00a0ClearFake campaigns are able to automate the process, either automatically putting the malicious command into the clipboard, or retrieving or running the malicious command upon interaction. Another frequently leveraged technique is <a href=\"https:\/\/techjacksolutions.com\/scc-intel\/seo-poisoned-fake-open-source-tool-sites-deliver-remus-stealer-and-animateclipper-via-tds-infrastructure\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">SEO poisoning<\/span><\/a>. It is mentioned regularly with Remus Stealer, but other families also leverage it. The technique involves designing malicious sites that appear at the top of search results, above legitimately relevant sites, to direct traffic to malicious sites.\u00a0<\/p>\n<p>Popular software and open source tools can be used as impersonation targets for these kinds of attacks. These are just a few examples of potential social engineering techniques, showing why it is important to stay cautious and skeptical when using the internet.\u00a0\u00a0<\/p>\n<h3>Why visibility is essential<\/h3>\n<p>Infostealers are all too common nowadays, especially considering how dangerous they are. Once downloaded, they exfiltrate many kinds of data, giving the attackers access to user information, login credentials, session tokens, crypto wallets, and more. Since they have such clear ways to generate revenue, they are appealing to threat actors, driving demand in the MaaS market and encouraging malware authors to innovate in the space and improve their products.\u00a0<\/p>\n<p>AuraStealer, ACRStealer, and Remus Stealer are prime examples of active MaaS families. Each of them is unique in their own way, and sees different patterns of use. Being aware of different infostealer families is crucial to maintaining a safe environment. In addition, being wary of phishing schemes commonly associated with infostealer downloads is another way to prevent their installation.\u00a0 <\/p>\n<h2 id=\"indicators-of-compromise-iocs\">Indicators of Compromise (IoCs)<\/h2>\n<h3>AuraStealer<\/h3>\n<p>Observed July 2026<\/p>\n<h3>Hashes<\/h3>\n<p><em>5b5434cc8bb3556075c6967d2ffee5a6b33793de07b9d4701bc63d369de63861<\/em><br \/><em>bfad1100bc3054dd26151c7acea412960ece04c3aa075ba323c10cf75c31a9a4<\/em><br \/><em>b8663c9c2832b92095660d1c674835acb12804e56839451e6ad9e78ed3c6d5df<\/em><br \/><em>134ab4b33ab555f3a77d43e94891698834a9b739b065764a702c7c52e3f4c15b<\/em><br \/><em>a6382ab6244d3d36036280e1ec3e438f442759b6917e6bc19bcb29f1d3d7e9ee<\/em><br \/><em>3575caf8bd87912689ebb1d13770990248f93c5d882db8c849bee02cb7c0abad<\/em><br \/><em>93389f4234f81358fa29c65473b5bfc3c60ab7b3c2189185988f03a66aeda66f<\/em><br \/><em>01718933eb502e4ec9d4b1210a88cb026882d615605dd8d7fbf1c4057b7c0867<\/em><br \/><em>397566a51d405c351e5134650463d5872e218682f7f34a5f314539d087837ea4<\/em><br \/><em>3efc1f87e3f0566daef895ddccf21dff9eb70fbea17ec7d60ba7fdceb35c1b5c<\/em><br \/><em>36cfccc84b21d9bb8b3eb93589870aea0b146fd9ba649b785d44bb8dafd82656<\/em><br \/><em>758769a19ce049454101441e8d9e29b02c13a62146a43fa7b5692cff09ddf302<\/em><br \/><em>6530b7c8d9c8a48d16c94670cc9755f09b0d09efa92d65fbd1f9c7ebadce6630<\/em><br \/><em>c805579d25000e5270305c926dee6fcc108efede9195c2bb442a6662ddaca995<\/em><br \/><em>9e77a7733be97f17a64c949ef061c9fe5b23ebf3b8a171cad8f4f094ecf62fc8<\/em><br \/><em>730e9e0bd0a41438d7d7af227f1441b4f9d8a54988e0add3a2e0fbd7312cc163<\/em><\/p>\n<h3>Download\/source locations:<\/h3>\n<p><em>http[:]\/\/91.92.242[.]236\/files-129312398\/files\/file_03e1dd22b8ec149f.exe<\/em><br \/><em>http[:]\/\/91.92.241[.]243\/files\/file_391c1e83ac309020.exe<\/em><br \/><em>http[:]\/\/85.239.147[.]6\/files\/Leetootoo\/random.exe<\/em><br \/><em>http[:]\/\/85.239.147[.]6\/files\/5851730241\/IQEr4wy.exe<\/em><br \/><em>http[:]\/\/158.94.208[.]7\/files\/8705834433\/8njNDcy.exe<\/em><br \/><em>http[:]\/\/158.94.211[.]222\/files\/1660459253\/W3Trdgs.exe<\/em><br \/><em>http[:]\/\/158.94.211[.]222\/files\/bur\/fast.exe<\/em><\/p>\n<h3>C2 domains<\/h3>\n<p><em>aimemtools[.]cfd<\/em><br \/><em>softwareguard[.]cfd<\/em><br \/><em>zkevopenanu[.]cfd<\/em><br \/><em>dev-tools[.]cfd<\/em><br \/><em>sys-tools[.]cfd<\/em><br \/><em>aewaterdelivery[.]com<\/em><br \/><em>secupd[.]cfd<\/em><br \/><em>memaiagent[.]cfd<\/em><\/p>\n<h3>Dropped\/Downloaded files<\/h3>\n<p><em>c4831ec2b68c576199245eb877e83f9b5e83dd3f<\/em><br \/><em>c4831ec2b68c576199245eb877e83f9b5e83dd3f<\/em><br \/><em>1c24da264bce471366156b4721bacb83201ba759<\/em><br \/><em>7c0f669cd06e5ba8fdcdba107b9519fe73519368<\/em><\/p>\n<h2 id=\"acrstealeramatera\">ACRStealer\/Amatera<\/h2>\n<p><em><strong>Observed July 2026<\/strong><\/em><\/p>\n<h3>Hashes<\/h3>\n<p><strong>Packed<\/strong><\/p>\n<p><em>0843ddfbe1908c5151495295ff7d1007b3c8bca287a766c437cea6b0e3f72f4d<\/em><br \/><em>e96c774b2c8425ab237b0fb36f57a7d8cc7e782b6d4e9a99434f3d21c93d5128<\/em><br \/><em>1019d8a20bd7732b2c2747b30646a5d10725fd5ee532b5e858dab27ba150db1e<\/em><br \/><em>06f6a0dc417bf0c8d1fa54754f53d37d190a3b9bf66658e00a630ae0bb56dfab<\/em><br \/><em>eecf2b15c3656275f7f4d4e1e4287fee795cb857790ca7eca107efa9cd6fad30<\/em><br \/><em>2ab248b392653566fe4fb34e2ced50acd8e91941010f38e2a85c792968261f20<\/em><br \/><em>69d4b349416a93227b332b50a0d6aa38ec522d528f31f4400f248b247fd607e3<\/em><br \/><em>f698f7919b026700cc2a2a9166258b8770ab9412122207f7b955fb97d249b8b9<\/em><br \/><em>41b3e4f80aa2deeaf56c5181cd3fc1b2ee545d053d29934408bb17ddd7ea2096<\/em><\/p>\n<p><strong>Unpacked<\/strong><\/p>\n<p><em>d7979fb0377c30a5361cd3f2f934c1e058a5c86031792dc66eeb24d6d7569661<\/em><br \/><em>4332227474b0d7db91a1e156ac3afa58ea4973ff00cb455dfd073fa1ec6dabcd<\/em><br \/><em>69a11394f6ee9d2af144f57d47632806f0760d5f1bdb69310a000b436ee3b5bc<\/em><br \/><em>9d02336c331bd335887c04ee466be41bc1a2a7e9069a9e9aaca2765484af0f14<\/em><br \/><em>b3708f27ddaebb5f2f256416e5082de39dd48d2a9b2bf0e9076794c3c4ca8506<\/em><br \/><em>aa1f23f90cd08417a86783f9c0f80c31cc621e852091f2e7ad724b89f74f11c8<\/em><br \/><em>510ce9e01292433f1e1163abb6a8896e3ebb2269a0489fa91a1dec7d54fec5c9<\/em><br \/><em>21c11f37cbf8365d26d243515cd23e822ecfa1d25f3262b62ffb1085efd09d9c<\/em><br \/><em>242871749873401e97d2651c5bc1c874ae9a3832a1c14b48630390dff0acafc0<\/em><br \/><em>9d93afbd9c5718fe14d9f24a080e8debc6b83f6596babe0aad1b3a9cb5013d01<\/em><br \/><em>0fac8922b1afc82d02b7a2d059ec6964a0b29196166b1377d165c08e134400db<\/em><br \/><em>c45357593df7614af68592c0f1ef578f824dc6c9d82f7a6198b21be7c06a57d6<\/em><br \/><em>900b639b26e321b308ecff93998ee33637bde2a9e198b42208ab70ff9dabe35e<\/em><br \/><em>e37280893d138dcc18a14ae4f5e4a13d71419da82ba978d7dcad510af95e86aa<\/em><br \/><em>2abb2d9250e78af3b0636a83f6031a14512d7d891e34a043cafc771f2ac3ea12<\/em><br \/><em>167873a847a2b996bd3b44b38c819768274efda6daf2978532c7b6b4f1a0acb1<\/em><br \/><em>127bfec23f77b6c9f2addd7f1fe8016b41078c8dbdda34737f7cb6b5563ec22b<\/em><br \/><em>4a3cf2cd75d78359f4ee1bc64703864781ffd8b93145c58a82078342b8097cef<\/em><br \/><em>641bcdaec2580058bfcbf8415ae123c7d9907c688cb107df79e20024e3bc23e2<\/em><br \/><em>ecde41aae4e4477a62781afdaa25c3020af8ff03008cc75e6fa0d140428abb63<\/em><br \/><em>252ad5844e88d5e3da533f8d913442cdc72d018ed29594a994e19a403026aa0d<\/em><br \/><em>377e1b540fd76b28638231ca69f955130768ea9de045e6af18b6e5b88e59211d<\/em><br \/><em>4c35c4ca7a9c5170587e4e8f0100f3730082e2a872e74129e38f26d3107e7e0c<\/em><br \/><em>8049545b6d7e2ae529a6c754c555164a79b4ebe90da7c56155c9a4282c01304d<\/em><br \/><em>e2c92e4a8d22fc18a4e7510fc7ea4a207be80c5028bdc25f2aa06f7aa21627db<\/em><br \/><em>a683c423efa53f048b26c3b1c530e2598d7b55833fbe3b198cd5f13a9986fb42<\/em><br \/><em>aaf61581328f2df00b47971c2b3882122ab7e52416dc4ac2a9637ea8255810f7<\/em><br \/><em>3fa65bbadec7e0d448b4d167ac48399f1f9a0966d5574b25876169171a204aba<\/em><br \/><em>bce365972cd411ba22eb09d29792d6bb52dc485be9552a45200502e168d733b5<\/em><br \/><em>47a7a38d8e7d729aa0d9312fae2ebd13b7c11a5ae91474a883b7ceb56298f395<\/em><br \/><em>86e69bc51a02e619fcae64815445b5d8232d38361d3b055677687621e9b29c7a<\/em><br \/><em>dd412434f9fb3d06b009c6e793938e88ab7edf71bf3180753edbcc5f1702f18e<\/em><br \/><em>e6a771b99ea4fa87af203a786608d3f7396d1698f43242905a66e6f9539df60e<\/em><br \/><em>5ce36e61c71aa43b274142d8be1cb6e38d4ed52336d7b76d06a761534c0da8c4<\/em><br \/><em>c42849a90763133a57b4e543a4af231837e54835d3ba9a5cd9130b9d66ea3bae<\/em><template id=\"P:10\"><\/template><template id=\"P:11\"><\/template><template id=\"P:12\"><\/template><template id=\"P:13\"><\/template><template id=\"P:14\"><\/template><template id=\"P:15\"><\/template><template id=\"P:16\"><\/template><template id=\"P:17\"><\/template><template id=\"P:18\"><\/template><template id=\"P:19\"><\/template><template id=\"P:1a\"><\/template><template id=\"P:1b\"><\/template><template id=\"P:1c\"><\/template><template id=\"P:1d\"><\/template><template id=\"P:1e\"><\/template><template id=\"P:1f\"><\/template><template id=\"P:20\"><\/template><template id=\"P:21\"><\/template><template id=\"P:22\"><\/template><template id=\"P:23\"><\/template><template id=\"P:24\"><\/template><template id=\"P:25\"><\/template><template id=\"P:26\"><\/template><template id=\"P:27\"><\/template><template id=\"P:28\"><\/template><template id=\"P:29\"><\/template><template id=\"P:2a\"><\/template><template id=\"P:2b\"><\/template><template id=\"P:2c\"><\/template><template id=\"P:2d\"><\/template><template id=\"P:2e\"><\/template><template id=\"P:2f\"><\/template><template id=\"P:30\"><\/template><template id=\"P:31\"><\/template><template id=\"P:32\"><\/template><template id=\"P:33\"><\/template><template id=\"P:34\"><\/template><template id=\"P:35\"><\/template><template id=\"P:36\"><\/template><template id=\"P:37\"><\/template><template id=\"P:38\"><\/template><template id=\"P:39\"><\/template><template id=\"P:3a\"><\/template><template id=\"P:3b\"><\/template><\/p>\n<h3>C2s<\/h3>\n<p><em>gw.portallbridge[.]cc<\/em><br \/><em>login.metricsdashboard[.]cc<\/em><br \/><em>static.quorashift[.]cc<\/em><br \/><em>data.nomadhive[.]cc<\/em><br \/><em>auth.automationportal[.]cc<\/em><br \/><em>wss.vectorplatform[.]cc<\/em><br \/><em>edge.kernelmonitor[.]cc<\/em><br \/><em>stream.pawpalace[.]cc<\/em><br \/><em>res.explicittweak[.]cc<\/em><\/p>\n<h2 id=\"remus-stealer\">Remus Stealer<\/h2>\n<p><em><strong>Observed August 2026<\/strong><\/em><\/p>\n<h3>Hashes<\/h3>\n<p><em>28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb<\/em><br \/><em>450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd<\/em><br \/><em>000b7533d53d0feed7cd995043a4298fe2b8c5767c1ffff7710f446c682928cb<\/em><br \/><em>2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be<\/em><br \/><em>48b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e<\/em><br \/><em>608057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da8<\/em><br \/><em>6f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f<\/em><br \/><em>55fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d1<\/em><br \/><em>47d5a5ef1afe3d1b8dbfde026a80d97ed0e012c144fa3940bb39758de75ca842<\/em><br \/><em>67cd5f1b19d33786a9f73b630357cce0d90d6771590ccb965fb331ffc6d4fb94<\/em><br \/><em>9935b9d36e8b6ac544a9a990bcccda8eb346596fbbcb5259bc929835b737c4d2<\/em><br \/><em>7e1e424f3c184c3c037235494158be38a9e7b15e0bd4a97c7f854ab03a1f09ed<\/em><br \/><em>84b8ec2f3b29a10f88d21fc7617cdfecac1c2c76303086b41471beb5f563f65c<\/em><br \/><em>99830a24d6aed654adff341b2c6ad2ba6c971c028dfce1ca455a37d1fbdf4617<\/em><br \/><em>ab8cee7ddbeb8d937f8a6855c52cee704bb6f4a10934fcaf17544a8c31cced39<\/em><br \/><em>b7c682fc6e8ea93f44c2c86fcd06e664971f42e8290a534c65a32a92d9b53a14<\/em><br \/><em>b40cb47ab1775a4be4ec9b997b58bedfeb2076079df0804dc80982c0309fa9a2<\/em><br \/><em>c1e0d2c9e04fcdb10ff2d4565758ceda1331fc80def548742a79b60be81da9b9<\/em><br \/><em>d3b08fd3ce1ca451b1dffd00c657b6ac1ad8ad769171faa1ba9688b572283d32<\/em><br \/><em>cd7c5860e0e6bdbc49ae5f07d85989469a41a108dede6f6086541d276ccc155f<\/em><br \/><em>e99d9294331c15c7ee0f4a03f8b95eda42fa065ec7d008bc326f9d8db562c118<\/em><br \/><em>de0d703c69ec8421a5351dc02735179aee12e8257b5816108feda8716b695b49<\/em><br \/><em>dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9<\/em><br \/><em>f68ba32766e087f5a6855fa7da9feea2968280a019aec31d7d173adcd4b848ca<\/em><br \/><em>f3ef2636d9b60715c2ea7c032cfd20492b7701bfa72ed3652b2bc540760988a0<\/em><br \/><em>fc8a7102ed41830084bcd7c4176a93366ad3c9ce0662cb006f15f01f763cb260<\/em><br \/><em>28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb<\/em><br \/><em>450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd<\/em><br \/><em>000b7533d53d0feed7cd995043a4298fe2b8c5767c1ffff7710f446c682928cb<\/em><br \/><em>2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be<\/em><br \/><em>48b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e<\/em><br \/><em>608057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da8<\/em><br \/><em>6f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f<\/em><br \/><em>55fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d1<\/em><br \/><em>47d5a5ef1afe3d1b8dbfde026a80d97ed0e012c144fa3940bb39758de75ca842<\/em><template id=\"P:3c\"><\/template><template id=\"P:3d\"><\/template><template id=\"P:3e\"><\/template><template id=\"P:3f\"><\/template><template id=\"P:40\"><\/template><template id=\"P:41\"><\/template><template id=\"P:42\"><\/template><template id=\"P:43\"><\/template><template id=\"P:44\"><\/template><template id=\"P:45\"><\/template><template id=\"P:46\"><\/template><template id=\"P:47\"><\/template><template id=\"P:48\"><\/template><template id=\"P:49\"><\/template><template id=\"P:4a\"><\/template><template id=\"P:4b\"><\/template><template id=\"P:4c\"><\/template><template id=\"P:4d\"><\/template><template id=\"P:4e\"><\/template><template id=\"P:4f\"><\/template><template id=\"P:50\"><\/template><template id=\"P:51\"><\/template><template id=\"P:52\"><\/template><template id=\"P:53\"><\/template><template id=\"P:54\"><\/template><template id=\"P:55\"><\/template><template id=\"P:56\"><\/template><template id=\"P:57\"><\/template><\/p>\n<h3>C2s<\/h3>\n<p><strong>URLs<\/strong><\/p>\n<p><em>hxxp[:\/\/]azurhay[.]shop:8539<\/em><br \/><em>hxxp[:\/\/]carogra[.]biz:4219<\/em><br \/><em>hxxp[:\/\/]fimmora[.]surf:6504<\/em><br \/><em>hxxp[:\/\/]freshis[.]biz:7752<\/em><br \/><em>hxxp[:\/\/]hooiuse[.]click:4938<\/em><br \/><em>hxxp[:\/\/]myrtler[.]biz:9549<\/em><br \/><em>hxxp[:\/\/]onesdto[.]shop:2535<\/em><br \/><em>hxxp[:\/\/]slyfogx[.]shop:5776<\/em><br \/><em>hxxp[:\/\/]topxgax[.]click:4930<\/em><br \/><em>hxxp[:\/\/]tzpx[.]courses:4437<\/em><br \/><em>hxxp[:\/\/]uiccvbk[.]click:8839<\/em><br \/><em>hxxp[:\/\/]youngel[.]biz:8768<\/em><br \/><em>hxxp[:\/\/]zelpx[.]garden:9895<\/em><\/p>\n<p><strong>Domains<\/strong><\/p>\n<p>azurhay[.]shop<br \/>carogra[.]biz<br \/>fimmora[.]surf<br \/>freshis[.]biz<br \/>hooiuse[.]click<br \/>myrtler[.]biz<br \/>onesdto[.]shop<br \/>slyfogx[.]shop<br \/>topxgax[.]click<br \/>tzpx[.]courses<br \/>uiccvbk[.]click<br \/>youngel[.]biz<br \/>zelpx[.]garden<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attackers are leveraging infostealer malware-as-a-service (MaaS) for a variety of attacks, with malware of this nature showing up regularly in a variety of campaign types. ReversingLabs found several specific infostealers being used recently: AuraStealer, a very actively updated and maintained stealer with recently improved anti-analysis features, ACRStealer, a long standing malware family that has fallen in and out of use, and RemusStealer, a new potential variant on the infamous LummaStealer.T<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26172","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26172","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26172"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26172\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26172"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26172"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26172"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}