CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains

Summary
CIS CTI traced Remus infostealer activity from March to September 2026 and analyzed three delivery chains. Remus targets browser credentials and sessions, which can help attackers bypass MFA, and supports blockchain-based C2 rotation.
Key points
- CIS CTI identified Remus activity through MS-ISAC member telemetry and analyzed three delivery chains; the report says the chains are not exhaustive.
- Remus targets Chromium and Firefox credentials, cookies, master keys and session tokens. Stealing authenticated sessions can help attackers bypass MFA.
- The chains use ClickFix with PLYCHIP staging, DonutLoader shellcode to run Remus in memory, and GoFlateLoader bundled with cracked software.
- In the ClickFix chain, a fake verification prompt copies a command to the clipboard. CIS did not directly observe that command executing, but assessed with moderate confidence that it leads through PLYCHIP to Remus.
- Remus can resolve C2 endpoints through an Ethereum smart contract, allowing operators to rotate addresses without registering new domains. CIS recommends blocking access to smart-contract services where there is no business need, while noting attackers may find workarounds.
- Remus encrypts its embedded C2 configuration with ChaCha20, but the key is stored in the payload; defenders can recover it from a captured sample to extract C2 addresses without detonating it.
- CIS shared more than 100 indicators of compromise with MS-ISAC members and recommends using threat intelligence and malicious-domain blocking to support defense.
Article Details
- Attack Vectors
- A ClickFix chain used JavaScript injected into a reportedly compromised site to present a fake verification prompt and place a remote command on the victim's clipboard. CIS CTI did not directly observe execution of the copied command, but assessed with moderate confidence that it led through PLYCHIP-hosted loader domains to Remus.
- PLYCHIP scripts screened machines for Workgroup or domain membership, installed antivirus and, in some variants, running analysis tools before fetching an encrypted payload.
- A separate chain used DonutLoader shellcode blobs to decrypt and map Remus into process memory. In one observed sequence, a downloader first saved and executed a loader PE.
- A cracked game installer bundled a Remus-delivering sample associated with GoFlateLoader.
- Defensive Notes
- Where there is no business need, defenders can block access to domains offering Ethereum smart-contract-related services. CIS CTI cautioned that operators may find workarounds.
- CIS CTI reported that defenders with a captured Remus sample can recover its embedded key, decrypt its configuration and extract C2 addresses without detonating the sample.
- CIS CTI recommended that U.S. State, Local, Tribal, and Territorial government organizations join the MS-ISAC for indicator sharing and its Malicious Domain Blocking and Reporting service.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | fightwa[.]biz | Remus C2 domain obtained through its Ethereum smart-contract resolver; the payload then contacted it on TCP port 5902. |
| DOMAIN | genuskox[.]biz | Remus C2 domain contacted by the cracked-game-installer sample on port 4378. |
| DOMAIN | one-verif[.]lol | Loader domain referenced by the ClickFix clipboard command and associated with the investigated Remus delivery chain. |
| DOMAIN | robinhuds[.]com | Remus domain identified by an alert and used to pivot to related C2 infrastructure. |
| IPV4 | 188[.]40[.]60[.]27 | IP address given for the genuskox[.]biz Remus C2 endpoint. |
| URL | hxxp[:]//31[.]77[.]168[.]180:5000/piva[.]exe | Example URL used by a downloader to retrieve a loader PE in the DonutLoader chain. |
| URL | hxxp[:]//31[.]77[.]168[.]180:5000/umvbr[.]bin | Example URL from which the loader fetched a shellcode blob carrying encrypted Remus. |
| URL | hxxp[:]//84[.]21[.]189[.]150:5000/rena[.]bin | Example URL from which a loader fetched a DonutLoader shellcode blob carrying encrypted Remus. |
| URL | hxxp[:]//josegza[.]biz:8521 | Example Remus C2 endpoint contacted after the in-memory payload was loaded. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationRemus encrypted its embedded C2 configuration with ChaCha20, and observed DonutLoader blobs carried encrypted Remus executables.T1041 · Exfiltration Over C2 ChannelPacket captures showed Remus exfiltrating through multipart POST requests to its C2 server.T1055 · Process InjectionCited open-source reporting says Remus obtains browser data through browser-process injection.T1059.001 · PowerShellPLYCHIP used PowerShell scripts for screening and staging; CIS CTI confirmed a Remus payload was decrypted and executed within a PowerShell process.T1070.004 · File DeletionObserved DonutLoader runs deleted the cached shellcode container, Prefetch entries and contents of %TEMP%.T1071.001 · Web ProtocolsRemus registered with C2 over HTTP on non-standard ports and used HTTP POST requests in its C2 communications.T1102.001 · Dead Drop ResolverWhen enabled, Remus queried an Ethereum smart contract through an RPC service to obtain a live C2 domain and port.T1105 · Ingress Tool TransferLoaders fetched shellcode blobs or a loader PE from remote URLs, while PLYCHIP fetched an encrypted final payload.T1113 · Screen CaptureCited open-source reporting identifies screenshot collection among Remus capabilities.T1115 · Clipboard DataCited open-source reporting identifies clipboard-content collection among Remus capabilities.T1497.001 · System ChecksThe injected JavaScript checked for browser-automation environments, while some PLYCHIP variants checked running processes for analysis tools.T1539 · Steal Web Session CookieCited open-source reporting says Remus targets browser cookies and authenticated sessions.T1555.003 · Credentials from Web BrowsersCited open-source reporting says Remus targets Chromium and Firefox browser credentials and master keys.T1620 · Reflective Code LoadingDonutLoader decrypted an embedded Remus PE and mapped it into process memory without writing that executable to disk.
Threat Actors
KongTukeThe article identifies KongTuke as another tracking name for LandUpdate808, also tracked as TAG-124; CIS CTI assessed the web-injection network was likely associated with it.LandUpdate808CIS CTI assessed that a web-injection network serving behaviorally similar files was likely associated with this multi-tenant traffic distribution system, also tracked as TAG-124 and KongTuke.TAG-124The article identifies TAG-124 as another tracking name for LandUpdate808, also tracked as KongTuke; CIS CTI assessed the web-injection network was likely associated with it.
Malware
GoFlateLoaderRemus subscriber delivery chains using ClickFix and PLYCHIP staging, DonutLoader shellcode, and GoFlateLoader bundled in cracked software lures.LummaC2Through Remus operator-published forum posts and cybersecurity company Gen Digital's code analysis, CIS CTI confirmed Remus traces its lineage to Lumma Stealer through an intermediate project called Tenzor.RemusHomeInsightsBlog PostsSLTT C2 Traffic Tied to Remus Malware Distribution Operation
Products
ChromiumOpen-source reporting from Flashpoint, aachum, and Check Point Research indicates Remus targets Chromium and Firefox browser credentials, cookies, and master keys via browser-process injection, clipboard content,Claudehad expanded its collection capabilities to target artificial intelligence (AI) clients including Claude, Codex, OpenCode, Cursor, and Devin.Codexhad expanded its collection capabilities to target artificial intelligence (AI) clients including Claude, Codex, OpenCode, Cursor, and Devin.Cursorcollection capabilities to target artificial intelligence (AI) clients including Claude, Codex, OpenCode, Cursor, and Devin.Devinto target artificial intelligence (AI) clients including Claude, Codex, OpenCode, Cursor, and Devin.Firefoxreporting from Flashpoint, aachum, and Check Point Research indicates Remus targets Chromium and Firefox browser credentials, cookies, and master keys via browser-process injection, clipboard content,OpenCodeits collection capabilities to target artificial intelligence (AI) clients including Claude, Codex, OpenCode, Cursor, and Devin.
Tools
ANY.RUNdecryption using Volexity's open-source donut-decryptor tool, with additional insight provided by ANY.RUN.donut-decryptorof the loader stub across all four blobs, and successful decryption using Volexity's open-source donut-decryptor tool, with additional insight provided by ANY.RUN.DonutLoader(CIRT), identified three distinct Remus subscriber delivery chains using ClickFix and PLYCHIP staging, DonutLoader shellcode, and GoFlateLoader bundled in cracked software lures.PLYCHIPResponse Team (CIRT), identified three distinct Remus subscriber delivery chains using ClickFix and PLYCHIP staging, DonutLoader shellcode, and GoFlateLoader bundled in cracked software lures.Tria.geCIS CIRT attributed the samples to DonutLoader through VirusTotal and Tria.ge[a] tagging, a byte-for-byte match of the loader stub across all four blobs, and successful decryption using Volexity's open-sourceVirusTotalGoogle Threat Intelligence (GTI), accessible through VirusTotal, defines PLYCHIP as a multi-stage PowerShell-based downloader and screening tool.