Infostealers highlight malware
Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialAttackers are leveraging infostealer malware-as-a-service (MaaS) for a variety of attacks, with malware of this nature showing up regularly in a variety of campaign types. ReversingLabs found several specific infostealers being used recently: AuraStealer, a very actively updated and maintained stealer with recently improved anti-analysis features, ACRStealer, a long standing malware family that has fallen in and out of use, and RemusStealer, a new potential variant on the infamous LummaStealer.
The samples covered were active in July through August of 2026. Here are the top infostealer MaaS trends, and the families that ReversingLabs has been researching. The goal is to provide readers with important knowledge of these threats, how they manifest, and what they are capable of — all of which is vital to know in the current threat landscape.
[ Get the report: Copy, Paste, Compromise: The Tale of ClickFix | See the webinar ]
Malware-as-a-service (MaaS) is becoming increasingly important in the security landscape. It lowers the barrier of entry for attackers, giving anyone access to malware without requiring coding knowledge. The MaaS market functions like any other market does, where the best products rise to the top. Vendors compete with each other to make the best products and grow their businesses. To engage in this massive market, potential customers can purchase subscriptions to the service, lifetime licenses, or join affiliate programs. Affiliate programs are common with ransomware-as-a-service, where the malware producer takes a cut of the earnings, and their customers, the ones doing the ransomware attack, take home the rest. The types of MaaS offered vary, with any type of malware being offered somewhere for a fee. Infostealers are especially popular, and are what this blog focuses on.
Infostealers do exactly what their name implies. Once installed, they take information from the device and exfiltrate it to the attacker. Common targets for infostealers include credentials, personal information, crypto wallet information, and session tokens. More specialized targets may include documents on the machine, clipboard data, recordings, browser cookies, or applications data. Since infostealers can exfiltrate a variety of things, attackers are able to leverage them in whatever way best suits their goals. These goals may be leaking documents with important corporate information, finding data to be used for blackmail, or compromising the logins for critical accounts. Any of these options could be disastrous for individuals or businesses. Whatever data the infostealer may be targeting, it is not information one would want to be revealed to threat actors.
Another important feature of infostealers, especially the popular ones operating as MaaS, is their stealth and evasion. Some infostealers, such as LummaStealer, use techniques like process hollowing and process injection. These techniques involve putting malicious code into an existing, trusted process, avoiding detection. Users on the device will not be able to detect infostealer activity easily, without knowing what to look for. Many infostealers have basic anti-analysis functionality, can detect antivirus, sandboxing, or use of VMs, and will terminate themselves if signs point to them being analyzed. AuraStealer, which will be discussed later, gives the user a prompt before continuing, which is likely meant to combat automated analysis.
Figure 1, Screenshot of prompt box asking user to enter a randomized string (pxDpRf) to continue.
Infostealers can delete themselves when finished, or will delete themselves upon detection of analysis tools and environments.
During the past few months, the threat research team at ReversingLabs has been investigating and reporting on various infostealers. Focus was put on families with significant recent activity, and researchers delved specifically into features of active strains. The following is a summary of the research into three specific families, AuraStealer, ACRStealer/Amatera, and Remus Stealer.
This trio of infostealers was specifically selected due to the recency of development and amount of use. ReversingLabs databases show that between June 1st and August 18th, AuraStealer had 26 samples submitted, ACRStealer had 397 (with an additional 81 for the related Amatera family) and Remus Stealer was the most prevalent with 606. Each of these counts are for unique executable samples that were submitted for the first time during the time frame.
Figure 2, A graph visualizing malware activity timeline for RemusStealer (red), AuraStealer (pink), ACRStealer (cyan), from June 1 to August 20 (Generated by Spectra Intelligence MCP).
AuraStealer and Remus Stealer are also newer families, having existed for less than a year, and don’t have as much data about them. The three are known for their ability to gather credentials from browsers and crypto wallets. All three are also tied to CIS countries and Russian language hacking forms, although there was no evidence found of direct relationships between the authors of these strains. They’re used in a variety of social engineering schemes, showing the vast array of potential attackers using these services.
AuraStealer is a relatively new player, emerging in July of 2025. It has gained significant momentum since. It is comparable to other infostealers, and while it doesn’t directly rip off any code, it functions similarly to its direct competitors. It seems to be positioning itself to overtake the niches of other popular infostealers, like its most direct competitor and comparison point, LummaStealer. In fact, many LummaStealer detections flag AuraStealer incorrectly, at least initially. It operated as a subscription model, with basic and premium tiers, which are charged on a monthly or yearly basis.
In practice, AuraStealer is used in a variety of attacks. Popular distribution methods leverage ClickFix and malicious short form videos. Researchers discovered that AuraStealer had a major transformation in summer of 2026 and this change brought virtualization. These virtualized files were directly observed by researchers at ReversingLabs. Virtualization is a technique that involves running custom commands through a virtual machine, which obfuscates and makes it harder to analyze. This change also immensely increased the filesize, bringing it from 500-700KB to 10MB.
ACRStealer is an interesting case. It’s been around for a while, starting out initially in 2018. From there, it acted as a low level infostealer, not earning much success. In 2022, they rebranded and significantly upgraded the malware. It went on for two years, but in the middle of 2024, the maintainers announced an indefinite hiatus. This hiatus would involve the continuation of ongoing subscriptions, but halted the process of onboarding any new affiliates. A few months after this announcement, a new malware emerged, labeling itself as Amatera. A specific management portal for Amatera was found, and the samples associated with the panel and the Amatera name were very similar to ACRStealer. Despite the distinction in name, the two families are very similar, and it is difficult to discern what differentiates the two. Both families are in use to this day.
Remus Stealer is the newest MaaS out of the three, having started at the very beginning of 2026. The first signs of Remus were in January and February, but researchers quickly caught onto it. What makes it compelling is the fact it seems to be a 64-bit variant of one of the most notorious infostealers: LummaStealer. LummaStealer is a flagship infostealer MaaS, maintaining prevalence even after a government raid of its infrastructure and the doxing of some of its key players. This comparison is drawn because Remus borrows a lot of Lumma’s traits, such as handling of string obfuscation, approach to application bound encryption (ABE) override, and design of control panels. Remus is unique for utilizing Etherhiding as a C2 communication method, a trait which Lumma does not have. Etherhiding uses Ethereum smart contracts to communicate their C2 domains, which is harder to detect, trace and block. The name “Remus” is derived from log identification strings in the code, and Lumma samples utilize a similar nomenclature with their own logs.
Reports emphasize Remus’s use in malvertising, SEO-poisoning and search redirection. It is also regularly used in ClickFix, fake reaCAPCTHA, and fake downloads. One particular campaign involved Traffic Distribution System (TDS) to make fake, malicious websites reach the top of Google search results for software related terms. These webpages would redirect into a Remus payload. Frequent organizational targets of Remus include healthcare, financial, government, MSPs, and tech, but it is also used in campaigns targeting individuals, especially through gaming communities. Currently, multiple loaders (Ameday, Gcleaner and OffLoader) are dropping Remus, and these samples utilize VMProtect or a Go-based delivery stage.
These families are delivered in a variety of ways. Being aware of potential vectors is a crucial step in staying safe. Social engineering is the typical means of getting MaaS onto victim devices. ClickFix and ClearFake are two popular methods attackers use to get victims to install malware. ClickFix is a social engineering technique designed to get a potential victim to run malicious commands on their own device. This typically occurs through malicious tech advice or fake reCAPTCHA verification. This technique is increasingly being seen on social media videos. ClearFake is a related technique, and has been consistently topping threat charts as something to look out for.
Leveraging Javascript, ClearFake campaigns are able to automate the process, either automatically putting the malicious command into the clipboard, or retrieving or running the malicious command upon interaction. Another frequently leveraged technique is SEO poisoning. It is mentioned regularly with Remus Stealer, but other families also leverage it. The technique involves designing malicious sites that appear at the top of search results, above legitimately relevant sites, to direct traffic to malicious sites.
Popular software and open source tools can be used as impersonation targets for these kinds of attacks. These are just a few examples of potential social engineering techniques, showing why it is important to stay cautious and skeptical when using the internet.
Infostealers are all too common nowadays, especially considering how dangerous they are. Once downloaded, they exfiltrate many kinds of data, giving the attackers access to user information, login credentials, session tokens, crypto wallets, and more. Since they have such clear ways to generate revenue, they are appealing to threat actors, driving demand in the MaaS market and encouraging malware authors to innovate in the space and improve their products.
AuraStealer, ACRStealer, and Remus Stealer are prime examples of active MaaS families. Each of them is unique in their own way, and sees different patterns of use. Being aware of different infostealer families is crucial to maintaining a safe environment. In addition, being wary of phishing schemes commonly associated with infostealer downloads is another way to prevent their installation.
Observed July 2026
5b5434cc8bb3556075c6967d2ffee5a6b33793de07b9d4701bc63d369de63861
bfad1100bc3054dd26151c7acea412960ece04c3aa075ba323c10cf75c31a9a4
b8663c9c2832b92095660d1c674835acb12804e56839451e6ad9e78ed3c6d5df
134ab4b33ab555f3a77d43e94891698834a9b739b065764a702c7c52e3f4c15b
a6382ab6244d3d36036280e1ec3e438f442759b6917e6bc19bcb29f1d3d7e9ee
3575caf8bd87912689ebb1d13770990248f93c5d882db8c849bee02cb7c0abad
93389f4234f81358fa29c65473b5bfc3c60ab7b3c2189185988f03a66aeda66f
01718933eb502e4ec9d4b1210a88cb026882d615605dd8d7fbf1c4057b7c0867
397566a51d405c351e5134650463d5872e218682f7f34a5f314539d087837ea4
3efc1f87e3f0566daef895ddccf21dff9eb70fbea17ec7d60ba7fdceb35c1b5c
36cfccc84b21d9bb8b3eb93589870aea0b146fd9ba649b785d44bb8dafd82656
758769a19ce049454101441e8d9e29b02c13a62146a43fa7b5692cff09ddf302
6530b7c8d9c8a48d16c94670cc9755f09b0d09efa92d65fbd1f9c7ebadce6630
c805579d25000e5270305c926dee6fcc108efede9195c2bb442a6662ddaca995
9e77a7733be97f17a64c949ef061c9fe5b23ebf3b8a171cad8f4f094ecf62fc8
730e9e0bd0a41438d7d7af227f1441b4f9d8a54988e0add3a2e0fbd7312cc163
http[:]//91.92.242[.]236/files-129312398/files/file_03e1dd22b8ec149f.exe
http[:]//91.92.241[.]243/files/file_391c1e83ac309020.exe
http[:]//85.239.147[.]6/files/Leetootoo/random.exe
http[:]//85.239.147[.]6/files/5851730241/IQEr4wy.exe
http[:]//158.94.208[.]7/files/8705834433/8njNDcy.exe
http[:]//158.94.211[.]222/files/1660459253/W3Trdgs.exe
http[:]//158.94.211[.]222/files/bur/fast.exe
aimemtools[.]cfd
softwareguard[.]cfd
zkevopenanu[.]cfd
dev-tools[.]cfd
sys-tools[.]cfd
aewaterdelivery[.]com
secupd[.]cfd
memaiagent[.]cfd
c4831ec2b68c576199245eb877e83f9b5e83dd3f
c4831ec2b68c576199245eb877e83f9b5e83dd3f
1c24da264bce471366156b4721bacb83201ba759
7c0f669cd06e5ba8fdcdba107b9519fe73519368
Observed July 2026
Packed
0843ddfbe1908c5151495295ff7d1007b3c8bca287a766c437cea6b0e3f72f4d
e96c774b2c8425ab237b0fb36f57a7d8cc7e782b6d4e9a99434f3d21c93d5128
1019d8a20bd7732b2c2747b30646a5d10725fd5ee532b5e858dab27ba150db1e
06f6a0dc417bf0c8d1fa54754f53d37d190a3b9bf66658e00a630ae0bb56dfab
eecf2b15c3656275f7f4d4e1e4287fee795cb857790ca7eca107efa9cd6fad30
2ab248b392653566fe4fb34e2ced50acd8e91941010f38e2a85c792968261f20
69d4b349416a93227b332b50a0d6aa38ec522d528f31f4400f248b247fd607e3
f698f7919b026700cc2a2a9166258b8770ab9412122207f7b955fb97d249b8b9
41b3e4f80aa2deeaf56c5181cd3fc1b2ee545d053d29934408bb17ddd7ea2096
Unpacked
d7979fb0377c30a5361cd3f2f934c1e058a5c86031792dc66eeb24d6d7569661
4332227474b0d7db91a1e156ac3afa58ea4973ff00cb455dfd073fa1ec6dabcd
69a11394f6ee9d2af144f57d47632806f0760d5f1bdb69310a000b436ee3b5bc
9d02336c331bd335887c04ee466be41bc1a2a7e9069a9e9aaca2765484af0f14
b3708f27ddaebb5f2f256416e5082de39dd48d2a9b2bf0e9076794c3c4ca8506
aa1f23f90cd08417a86783f9c0f80c31cc621e852091f2e7ad724b89f74f11c8
510ce9e01292433f1e1163abb6a8896e3ebb2269a0489fa91a1dec7d54fec5c9
21c11f37cbf8365d26d243515cd23e822ecfa1d25f3262b62ffb1085efd09d9c
242871749873401e97d2651c5bc1c874ae9a3832a1c14b48630390dff0acafc0
9d93afbd9c5718fe14d9f24a080e8debc6b83f6596babe0aad1b3a9cb5013d01
0fac8922b1afc82d02b7a2d059ec6964a0b29196166b1377d165c08e134400db
c45357593df7614af68592c0f1ef578f824dc6c9d82f7a6198b21be7c06a57d6
900b639b26e321b308ecff93998ee33637bde2a9e198b42208ab70ff9dabe35e
e37280893d138dcc18a14ae4f5e4a13d71419da82ba978d7dcad510af95e86aa
2abb2d9250e78af3b0636a83f6031a14512d7d891e34a043cafc771f2ac3ea12
167873a847a2b996bd3b44b38c819768274efda6daf2978532c7b6b4f1a0acb1
127bfec23f77b6c9f2addd7f1fe8016b41078c8dbdda34737f7cb6b5563ec22b
4a3cf2cd75d78359f4ee1bc64703864781ffd8b93145c58a82078342b8097cef
641bcdaec2580058bfcbf8415ae123c7d9907c688cb107df79e20024e3bc23e2
ecde41aae4e4477a62781afdaa25c3020af8ff03008cc75e6fa0d140428abb63
252ad5844e88d5e3da533f8d913442cdc72d018ed29594a994e19a403026aa0d
377e1b540fd76b28638231ca69f955130768ea9de045e6af18b6e5b88e59211d
4c35c4ca7a9c5170587e4e8f0100f3730082e2a872e74129e38f26d3107e7e0c
8049545b6d7e2ae529a6c754c555164a79b4ebe90da7c56155c9a4282c01304d
e2c92e4a8d22fc18a4e7510fc7ea4a207be80c5028bdc25f2aa06f7aa21627db
a683c423efa53f048b26c3b1c530e2598d7b55833fbe3b198cd5f13a9986fb42
aaf61581328f2df00b47971c2b3882122ab7e52416dc4ac2a9637ea8255810f7
3fa65bbadec7e0d448b4d167ac48399f1f9a0966d5574b25876169171a204aba
bce365972cd411ba22eb09d29792d6bb52dc485be9552a45200502e168d733b5
47a7a38d8e7d729aa0d9312fae2ebd13b7c11a5ae91474a883b7ceb56298f395
86e69bc51a02e619fcae64815445b5d8232d38361d3b055677687621e9b29c7a
dd412434f9fb3d06b009c6e793938e88ab7edf71bf3180753edbcc5f1702f18e
e6a771b99ea4fa87af203a786608d3f7396d1698f43242905a66e6f9539df60e
5ce36e61c71aa43b274142d8be1cb6e38d4ed52336d7b76d06a761534c0da8c4
c42849a90763133a57b4e543a4af231837e54835d3ba9a5cd9130b9d66ea3bae
gw.portallbridge[.]cc
login.metricsdashboard[.]cc
static.quorashift[.]cc
data.nomadhive[.]cc
auth.automationportal[.]cc
wss.vectorplatform[.]cc
edge.kernelmonitor[.]cc
stream.pawpalace[.]cc
res.explicittweak[.]cc
Observed August 2026
28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb
450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd
000b7533d53d0feed7cd995043a4298fe2b8c5767c1ffff7710f446c682928cb
2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be
48b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e
608057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da8
6f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f
55fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d1
47d5a5ef1afe3d1b8dbfde026a80d97ed0e012c144fa3940bb39758de75ca842
67cd5f1b19d33786a9f73b630357cce0d90d6771590ccb965fb331ffc6d4fb94
9935b9d36e8b6ac544a9a990bcccda8eb346596fbbcb5259bc929835b737c4d2
7e1e424f3c184c3c037235494158be38a9e7b15e0bd4a97c7f854ab03a1f09ed
84b8ec2f3b29a10f88d21fc7617cdfecac1c2c76303086b41471beb5f563f65c
99830a24d6aed654adff341b2c6ad2ba6c971c028dfce1ca455a37d1fbdf4617
ab8cee7ddbeb8d937f8a6855c52cee704bb6f4a10934fcaf17544a8c31cced39
b7c682fc6e8ea93f44c2c86fcd06e664971f42e8290a534c65a32a92d9b53a14
b40cb47ab1775a4be4ec9b997b58bedfeb2076079df0804dc80982c0309fa9a2
c1e0d2c9e04fcdb10ff2d4565758ceda1331fc80def548742a79b60be81da9b9
d3b08fd3ce1ca451b1dffd00c657b6ac1ad8ad769171faa1ba9688b572283d32
cd7c5860e0e6bdbc49ae5f07d85989469a41a108dede6f6086541d276ccc155f
e99d9294331c15c7ee0f4a03f8b95eda42fa065ec7d008bc326f9d8db562c118
de0d703c69ec8421a5351dc02735179aee12e8257b5816108feda8716b695b49
dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9
f68ba32766e087f5a6855fa7da9feea2968280a019aec31d7d173adcd4b848ca
f3ef2636d9b60715c2ea7c032cfd20492b7701bfa72ed3652b2bc540760988a0
fc8a7102ed41830084bcd7c4176a93366ad3c9ce0662cb006f15f01f763cb260
28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb
450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd
000b7533d53d0feed7cd995043a4298fe2b8c5767c1ffff7710f446c682928cb
2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be
48b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e
608057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da8
6f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f
55fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d1
47d5a5ef1afe3d1b8dbfde026a80d97ed0e012c144fa3940bb39758de75ca842
URLs
hxxp[://]azurhay[.]shop:8539
hxxp[://]carogra[.]biz:4219
hxxp[://]fimmora[.]surf:6504
hxxp[://]freshis[.]biz:7752
hxxp[://]hooiuse[.]click:4938
hxxp[://]myrtler[.]biz:9549
hxxp[://]onesdto[.]shop:2535
hxxp[://]slyfogx[.]shop:5776
hxxp[://]topxgax[.]click:4930
hxxp[://]tzpx[.]courses:4437
hxxp[://]uiccvbk[.]click:8839
hxxp[://]youngel[.]biz:8768
hxxp[://]zelpx[.]garden:9895
Domains
azurhay[.]shop
carogra[.]biz
fimmora[.]surf
freshis[.]biz
hooiuse[.]click
myrtler[.]biz
onesdto[.]shop
slyfogx[.]shop
topxgax[.]click
tzpx[.]courses
uiccvbk[.]click
youngel[.]biz
zelpx[.]garden
SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work.
One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.