#remusstealer
My favorite Remus botnet C2 domain so far 😄

havelbeenpwned .net ⤵️
NICENIC INTERNATIONAL🇨🇳

103.211.219.238:4219⤵️
AS394695 PUBLIC-DOMAIN-REGISTRY 🇮🇳

Malware sample:
bazaar.abuse.ch/sample/75fce...

More #Remnus IOCs available on ThreatFox 🦊
threatfox.abuse.ch/browse/malwa...

/cc @troyhunt.com
May 6, 2026 at 10:24 AM
Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware

Hackers are cloning Ghidra, dnSpy, ILSpy and other free tool sites to spread Malware like RemusStealer, crypto clippers and loaders through fake downloads.
#hackernews #news
Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware
Hackers are cloning Ghidra, dnSpy, ILSpy and other free tool sites to spread Malware like RemusStealer, crypto clippers and loaders through fake downloads.
hackread.com
June 9, 2026 at 2:08 PM
Fake open-source tool sites are distributing malware via advanced TDS. Verify sources before downloading. #CyberSecurity #Malware #OpenSource #TDS #RemusStealer #AnimateClipper thedailytechfeed.com/malicious-si...
June 4, 2026 at 10:24 AM
Check Point Research found 100+ fake sites impersonating Ghidra, dnSpy, and SpiderFoot, using click hijacking and TDS gates to spread SessionGate, RemusStealer, and AnimateClipper. #Ghidra #dnSpy #SpiderFoot
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
Check Point Research exposed a large-scale campaign that impersonates trusted open-source and freeware projects such as Ghidra, dnSpy, and SpiderFoot to hijack download clicks and route users through a gated Traffic Distribution System. The same infrastructure was used to deliver SessionGate, RemusStealer, and AnimateClipper, showing that the operation mixed traffic monetization with downstream malware delivery. #Ghidra #dnSpy #SpiderFoot #SessionGate #RemusStealer #AnimateClipper
www.hendryadrian.com
June 3, 2026 at 7:45 PM
🚨 Fake software portals weaponize the first click

Check Point found 100+ impersonation sites using CloudFront-hosted TDS scripts to redirect downloads toward RemusStealer, AnimateClipper and SessionGate.

🔗 read more: research.checkpoint.com/2026/imperso...

#ransomNews #cybersecurity
June 4, 2026 at 11:37 AM
Critical CloudFront Malware Injection Hijacks Developer Searches – RemusStealer Delivers Stealthy Infostealer via Fake MEGA Downloads + Video

Introduction: A new, sophisticated malware campaign has been discovered targeting software developers, utilizing a trusted Amazon CloudFront CDN server to…
Critical CloudFront Malware Injection Hijacks Developer Searches – RemusStealer Delivers Stealthy Infostealer via Fake MEGA Downloads + Video
Introduction: A new, sophisticated malware campaign has been discovered targeting software developers, utilizing a trusted Amazon CloudFront CDN server to deliver a 64-bit information stealer. The attack begins with a seemingly legitimate search for an open-source C++ IDE, but a malicious JavaScript file loaded from a CloudFront domain injects code that redirects victims to fake download pages, ultimately delivering the Remus infostealer, which is equipped with advanced anti-analysis and data theft capabilities.
undercodetesting.com
May 22, 2026 at 9:53 PM
大規模ハッキングキャンペーン——GhidraやdnSpy、SpiderFootなどセキュリティツールを偽装し、広告収益の詐取とマルウェア配布を実施

偽装サイト100件超が信頼性の高いセキュリティツールを模倣SessionGate、RemusStealer、AnimateClipperを配布主目的はトラフィックによる収益化信頼性の高いオープンソースセキュリティツールを偽装し、開発者やセキュリティ研究者から広告収益を騙し取るとともにマルウェアを配布する、大
大規模ハッキングキャンペーン——GhidraやdnSpy、SpiderFootなどセキュリティツールを偽装し、広告収益の詐取とマルウェア配布を実施
偽装サイト100件超が信頼性の高いセキュリティツールを模倣SessionGate、RemusStealer、AnimateClipperを配布主目的はトラフィックによる収益化信頼性の高いオープンソースセキュリティツールを偽装し、開発者やセキュリティ研究者から広告収益を騙し取るとともにマルウェアを配布する、大
blackhatnews.tokyo
June 4, 2026 at 10:05 AM
3/ Delivery is the boring part: ClickFix, ClearFake, and SEO-poisoned pages impersonating open-source tools. Full breakdown and IoCs: reversinglabs.com/blog/infoste... #ThreatIntel
Infostealers highlight malware-as-a-service trend | RL Blog
Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.
reversinglabs.com
August 28, 2026 at 12:41 PM
Check Point Research exposed fake open-source and freeware sites that hijacked search traffic through click-driven redirects, sending selected users to RemusStealer, AnimateClipper, and SessionGate. #ClickFix #TDS #CloudFront
Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive
Check Point Research uncovered a large-scale operation that impersonated open-source and freeware projects to capture search traffic through deceptive sites and click-driven redirects. The traffic was funneled through a CloudFront-hosted JavaScript staging layer and TDS chains that ultimately pointed selected users to RemusStealer, AnimateClipper, and the SessionGate framework. #CheckPointResearch #CloudFront #RemusStealer #AnimateClipper #SessionGate
www.hendryadrian.com
July 27, 2026 at 11:45 PM
Your security tools might have missed this one. RemusStealer is actively targeting networks right now — here's what you need to know before it hits yours.

Full analysis: threatchain.io/remusstealer-sample-detected-bootstrapper-exe-beff95d5

#cybersecurity #threatintelligence #infosec
May 26, 2026 at 7:19 PM
📣🚨 Watch out as hackers are cloning Ghidra, dnSpy, ILSpy and other free tool sites to spread malware through fake downloads, including RemusStealer, crypto clippers and loaders.

Read: hackread.com/hackers-clon...

#Cybersecurity #Malware #Ghidra #dnSpy #RemusStealer
Hackers Clone Ghidra, dnSpy and Other Tool Sites to Spread Malware
Hackers are cloning Ghidra, dnSpy, ILSpy and other free tool sites to spread Malware like RemusStealer, crypto clippers and loaders through fake downloads.
hackread.com
June 8, 2026 at 5:01 PM
~Checkpoint~
Fake open-source tool sites use click hijacking and TDS to deliver SessionGate, RemusStealer, and AnimateClipper.
-
IOCs: appfreshstart[. ]com, buccstanor[. ]pics, kr[. ]hugo-lapp[. ]co
-
#Malware #TDS #ThreatIntel
Malware Distribution via Impersonation & TDS
research.checkpoint.com
June 3, 2026 at 4:05 PM