CIS Links SLTT Remus C2 Traffic to Three Malware Delivery Chains
CIS CTI traced Remus infostealer activity from March to September 2026 and analyzed three delivery chains. Remus targets browser credentials and sessions, which can help attackers bypass MFA, and supports blockchain-based C2 rotation.