Malware · 139 days ago
REMUS is no longer just a password stealer. Its real value is session and token theft, which lets attackers keep using accounts after a reset or MFA change and turns one infected browser into lasting access across SaaS, email, and other session-based services.
Flare reviewed 128 underground posts from February 12 to May 8, 2026 and found the operation rapidly professionalizing. The posts show commercialization, automation, persistence features, and explicit targeting of password managers and browser sessions, with the malware presented like a maintained malware-as-a-service platform rather than a static stealer build.
That shift changes the response model. Cleaning the endpoint does not automatically revoke what was already stolen, and token monetization gives operators a longer-lived revenue stream than commodity credential theft usually allows.
1 source covering this story
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
Flare explains how the REMUS infostealer evolved around session theft and operational scalability.
Part of the PlainSec briefing for 2026-05-16