Same stealing arsenal, same techniques, new name. Is Remus the Lumma rebrand we've been waiting for?
Main attribution indicators:
→ The same Application-Bound Encryption bypass employed specifically by Remus and Lumma
→ Transitional test builds ("Tenzor") that share a Steam dead drop resolver with confirmed Lumma samples
→ Matching AntiVM cpuid checks against five hypervisor signatures in identical order
→ Shared direct syscall/sysenter architecture→ Identical per-string obfuscation technique
Remus also introduces notable changes: traditional Steam and Telegram dead drop resolvers are replaced by EtherHiding, with C2 addresses stored in Ethereum smart contracts, making the infrastructure even more resilient to takedown operations.
Remus: Unmasking The 64-bit Variant of the Infamous Lumma Stealer
The Lumma Rebrand We’ve Been Waiting For?

