🚨 Remus Stealer Advertised as Malware-as-a-Service with Tiered Subscriptions
A threat actor is advertising an information-stealing malware platform called Remus through an underground forum. The service is promoted as a subscription-based product offering configurable malware builds, automated processing of stolen data, Telegram notifications and access to a web-based management panel. According to the seller, customers also receive continuous technical support and access to infrastructure designed to manage infected devices and collected information. These claims originate from promotional material published by the alleged operator and have not been independently verified. Claimed Data-Collection Capabilities The seller claims that Remus can extract information from numerous browsers, cryptocurrency wallets and desktop applications. Advertised targets reportedly include: - credentials and saved passwords; - browser cookies and autofill information; - browsing history and saved notes; - payment-card information; - cryptocurrency seed phrases and private keys; - cryptocurrency wallet files; - MetaMask information; - browser-based wallet extensions; - password-manager extensions; - note-taking extensions; - two-factor authentication extensions; - selected files from folders configured by the operator. The promotional material claims support for data collection from 21 browsers, 16 cold-wallet products and 38 applications. It also advertises compatibility with numerous Chromium and Mozilla extensions. These figures should be treated as unverified marketing claims rather than confirmed technical findings. File Collection Remus is reportedly able to search selected directories and collect matching files. The alleged operator claims that customers can configure: - directory paths; - filename masks; - search depth; - excluded locations; - maximum file sizes; - collection rules for individual malware builds. No independent analysis has confirmed the reliability or extent of these capabilities. Management Panel The advertised control panel reportedly allows operators to review, search and export collected information. Claimed panel features include: - statistics for complete and incomplete logs; - filters for passwords, cookies and browser history; - combined AND/OR search conditions; - predefined targeting filters; - browser-based log viewing; - multiple simultaneous export tasks; - individual statistics for each malware build; - configurable collection profiles; - Telegram alerts and callback notifications; - team accounts and permission controls; - support for operator-managed collection servers. The seller also claims that collection infrastructure can be deployed using Docker. This does not confirm that the advertised service functions as described. Claimed Technical Characteristics The promotional post describes Remus as a C++ application with a relatively small executable footprint. Its alleged technical features include: - direct interaction with Windows system functions; - a custom client-server communication protocol; - encrypted configuration data; - encrypted transmission of collected information; - compressed log archives; - local caching and backup servers; - a microservice-based backend; - build obfuscation; - virtual-machine and analysis-environment detection; - claimed evasion of endpoint detection systems. The operator additionally advertises an automated MetaMask wallet brute-force capability. This particularly serious claim remains unverified and should not be treated as evidence that the feature exists or works. Advertised Subscription Prices The alleged service is being promoted using three subscription levels: - Base — $250 per month - Pro — $500 per month - Enterprise — $1,000 per month Higher-priced plans reportedly provide additional malware builds, filters, Telegram bots, loader functionality, concurrent exports, team accounts, worker dashboards, API access and more granular permissions. Some plans are also advertised as supporting DLL, PowerShell or in-memory execution methods. These are seller-provided claims and have not been validated through independent technical analysis. Assessment The advertisement presents Remus as a commercially managed information-stealing platform rather than a standalone malware sample. Its subscription model, customer support, management interface and tiered functionality are consistent with the broader malware-as-a-service ecosystem. However, underground sellers frequently exaggerate capabilities, detection rates and infection statistics. Promotional figures, particularly the claimed callback rate and security-product bypass capabilities, should be treated with caution. At the time of publication: - the identity of the operator has not been confirmed; - the advertised capabilities have not been independently reproduced; - the number of active customers or infections is unknown; - the claimed detection-evasion features remain unverified; - no conclusion should be drawn solely from the seller's promotional material. Safety Notice Do not download, execute or redistribute suspected Remus samples outside an appropriately isolated malware-analysis environment. Potential victims should change exposed credentials from a clean device, terminate active sessions, review cryptocurrency-wallet activity and contact the relevant financial or security provider when compromise is suspected. Verification Status Unverified. This report describes claims made in an underground advertisement. It does not independently confirm the malware's functionality, infection count, operator identity or commercial activity. Link available to registered users
Technology News