Remus Malware Leverages Ethereum Smart Contract for Dynamic C2 Infrastructure
Researchers have discovered a new Remus infostealer campaign that uses an Ethereum smart contract as a dead-drop resolver to dynamically steer victims' browsers to rotating command-and-control (C2) infrastructure.
The campaign targets Turkish-language speakers with fake cracked software lures and SEO poisoning, leading to the execution of a primary binary that performs process injection into live Chromium-based browser processes.
Remus then collects OS-level encrypted master keys from 'Local State' files, decrypts saved passwords, cookies, autofill data, and history, and targets browser extensions associated with cryptocurrency wallets by their extension IDs to harvest wallet configuration and session artifacts.