SpyCloud: Remus Windows infostealer — ClickFix, syscall unhook, browsers/wallets + AI credentials
SpyCloud (published 10 September 2026; Cyber Security News amplify 21 September) reverse-engineers Remus, a Windows information stealer that appeared on underground markets around March 2026. Collection: data from 21 browsers and 16 cold wallets, an unusually broad set of Mozilla extensions including 2FA tools, plus recent builds that steal AI credential folders used by Anthropic, OpenAI and other providers (API tokens and LLM usage history). Delivery commonly via ClickFix fake-CAPTCHA lures (email, malvertising, compromised sites) that persuade the victim to run a command. Evasion: OLLVM-style string/arithmetic obfuscation overlapping LummaC2 tooling lineage; pre-run syscall-hook sweep that removes EDR hooks; ChaCha20-encrypted C2 table; Outlook .pst honey@pot.com sandbox check. Distinct from desk card okta-ai-token-infostealer-20260909 (Okta TI on replayable AI session tokens in stealer logs generally) — this card is the Remus family analysis. No CVE.
- Product
- Windows endpoints; Chromium/Firefox browsers; crypto cold wallets; AI CLI/assistant credential stores
- Versions
- n/a (malware family; marketplace since ~Mar 2026; AI-credential theft in recent builds)
- Exploited in Australia?
- unknown
- Patch to
- Block ClickFix tradecraft (fake CAPTCHA → Win+R / PowerShell paste); hunt Remus IoCs per SpyCloud; rotate browser, wallet, 2FA-extension and AI provider API tokens from any infected host; treat stealer logs as live session risk for AI/SaaS accounts.
Primary: SpyCloud — Remus: A New Infostealer Hunting Wallets, Passwords, and AI Credentials (10 Sep 2026) · Vendor: SpyCloud primary malware analysis · Cyber Security News — Remus syscall-unhook / ClickFix amplify (21 Sep 2026)
