CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains

· Original article ↗

Summary

CIS CTI traced Remus infostealer activity from March to September 2026 and analyzed three delivery chains. Remus targets browser credentials and sessions, which can help attackers bypass MFA, and supports blockchain-based C2 rotation.

Key points

  • CIS CTI identified Remus activity through MS-ISAC member telemetry and analyzed three delivery chains; the report says the chains are not exhaustive.
  • Remus targets Chromium and Firefox credentials, cookies, master keys and session tokens. Stealing authenticated sessions can help attackers bypass MFA.
  • The chains use ClickFix with PLYCHIP staging, DonutLoader shellcode to run Remus in memory, and GoFlateLoader bundled with cracked software.
  • In the ClickFix chain, a fake verification prompt copies a command to the clipboard. CIS did not directly observe that command executing, but assessed with moderate confidence that it leads through PLYCHIP to Remus.
  • Remus can resolve C2 endpoints through an Ethereum smart contract, allowing operators to rotate addresses without registering new domains. CIS recommends blocking access to smart-contract services where there is no business need, while noting attackers may find workarounds.
  • Remus encrypts its embedded C2 configuration with ChaCha20, but the key is stored in the payload; defenders can recover it from a captured sample to extract C2 addresses without detonating it.
  • CIS shared more than 100 indicators of compromise with MS-ISAC members and recommends using threat intelligence and malicious-domain blocking to support defense.

Article Details

Attack Vectors
  • A ClickFix chain used JavaScript injected into a reportedly compromised site to present a fake verification prompt and place a remote command on the victim's clipboard. CIS CTI did not directly observe execution of the copied command, but assessed with moderate confidence that it led through PLYCHIP-hosted loader domains to Remus.
  • PLYCHIP scripts screened machines for Workgroup or domain membership, installed antivirus and, in some variants, running analysis tools before fetching an encrypted payload.
  • A separate chain used DonutLoader shellcode blobs to decrypt and map Remus into process memory. In one observed sequence, a downloader first saved and executed a loader PE.
  • A cracked game installer bundled a Remus-delivering sample associated with GoFlateLoader.
Defensive Notes
  • Where there is no business need, defenders can block access to domains offering Ethereum smart-contract-related services. CIS CTI cautioned that operators may find workarounds.
  • CIS CTI reported that defenders with a captured Remus sample can recover its embedded key, decrypt its configuration and extract C2 addresses without detonating the sample.
  • CIS CTI recommended that U.S. State, Local, Tribal, and Territorial government organizations join the MS-ISAC for indicator sharing and its Malicious Domain Blocking and Reporting service.

Indicators of compromise

TypeIndicatorContext
DOMAINfightwa[.]bizRemus C2 domain obtained through its Ethereum smart-contract resolver; the payload then contacted it on TCP port 5902.
DOMAINgenuskox[.]bizRemus C2 domain contacted by the cracked-game-installer sample on port 4378.
DOMAINone-verif[.]lolLoader domain referenced by the ClickFix clipboard command and associated with the investigated Remus delivery chain.
DOMAINrobinhuds[.]comRemus domain identified by an alert and used to pivot to related C2 infrastructure.
IPV4188[.]40[.]60[.]27IP address given for the genuskox[.]biz Remus C2 endpoint.
URLhxxp[:]//31[.]77[.]168[.]180:5000/piva[.]exeExample URL used by a downloader to retrieve a loader PE in the DonutLoader chain.
URLhxxp[:]//31[.]77[.]168[.]180:5000/umvbr[.]binExample URL from which the loader fetched a shellcode blob carrying encrypted Remus.
URLhxxp[:]//84[.]21[.]189[.]150:5000/rena[.]binExample URL from which a loader fetched a DonutLoader shellcode blob carrying encrypted Remus.
URLhxxp[:]//josegza[.]biz:8521Example Remus C2 endpoint contacted after the in-memory payload was loaded.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationRemus encrypted its embedded C2 configuration with ChaCha20, and observed DonutLoader blobs carried encrypted Remus executables.T1041 · Exfiltration Over C2 ChannelPacket captures showed Remus exfiltrating through multipart POST requests to its C2 server.T1055 · Process InjectionCited open-source reporting says Remus obtains browser data through browser-process injection.T1059.001 · PowerShellPLYCHIP used PowerShell scripts for screening and staging; CIS CTI confirmed a Remus payload was decrypted and executed within a PowerShell process.T1070.004 · File DeletionObserved DonutLoader runs deleted the cached shellcode container, Prefetch entries and contents of %TEMP%.T1071.001 · Web ProtocolsRemus registered with C2 over HTTP on non-standard ports and used HTTP POST requests in its C2 communications.T1102.001 · Dead Drop ResolverWhen enabled, Remus queried an Ethereum smart contract through an RPC service to obtain a live C2 domain and port.T1105 · Ingress Tool TransferLoaders fetched shellcode blobs or a loader PE from remote URLs, while PLYCHIP fetched an encrypted final payload.T1113 · Screen CaptureCited open-source reporting identifies screenshot collection among Remus capabilities.T1115 · Clipboard DataCited open-source reporting identifies clipboard-content collection among Remus capabilities.T1497.001 · System ChecksThe injected JavaScript checked for browser-automation environments, while some PLYCHIP variants checked running processes for analysis tools.T1539 · Steal Web Session CookieCited open-source reporting says Remus targets browser cookies and authenticated sessions.T1555.003 · Credentials from Web BrowsersCited open-source reporting says Remus targets Chromium and Firefox browser credentials and master keys.T1620 · Reflective Code LoadingDonutLoader decrypted an embedded Remus PE and mapped it into process memory without writing that executable to disk.

Threat Actors

Malware

Products

Tools

Countries

Industries

Related Articles