threat_intelligence1957 wordsRead on Arc Codex

Infostealers highlight malware

Spectra Assure Free Trial Get your 14-day free trial of Spectra Assure for Software Supply Chain Security Get Free TrialMore about Spectra Assure Free TrialAttackers are leveraging infostealer malware-as-a-service (MaaS) for a variety of attacks, with malware of this nature showing up regularly in a variety of campaign types. ReversingLabs found several specific infostealers being used recently: AuraStealer, a very actively updated and maintained stealer with recently improved anti-analysis features, ACRStealer, a long standing malware family that has fallen in and out of use, and RemusStealer, a new potential variant on the infamous LummaStealer. The samples covered were active in July through August of 2026. Here are the top infostealer MaaS trends, and the families that ReversingLabs has been researching. The goal is to provide readers with important knowledge of these threats, how they manifest, and what they are capable of — all of which is vital to know in the current threat landscape. [ Get the report: Copy, Paste, Compromise: The Tale of ClickFix | See the webinar ] Malware-as-a-service (MaaS) is becoming increasingly important in the security landscape. It lowers the barrier of entry for attackers, giving anyone access to malware without requiring coding knowledge. The MaaS market functions like any other market does, where the best products rise to the top. Vendors compete with each other to make the best products and grow their businesses. To engage in this massive market, potential customers can purchase subscriptions to the service, lifetime licenses, or join affiliate programs. Affiliate programs are common with ransomware-as-a-service, where the malware producer takes a cut of the earnings, and their customers, the ones doing the ransomware attack, take home the rest. The types of MaaS offered vary, with any type of malware being offered somewhere for a fee. Infostealers are especially popular, and are what this blog focuses on. Infostealers do exactly what their name implies. Once installed, they take information from the device and exfiltrate it to the attacker. Common targets for infostealers include credentials, personal information, crypto wallet information, and session tokens. More specialized targets may include documents on the machine, clipboard data, recordings, browser cookies, or applications data. Since infostealers can exfiltrate a variety of things, attackers are able to leverage them in whatever way best suits their goals. These goals may be leaking documents with important corporate information, finding data to be used for blackmail, or compromising the logins for critical accounts. Any of these options could be disastrous for individuals or businesses. Whatever data the infostealer may be targeting, it is not information one would want to be revealed to threat actors. Another important feature of infostealers, especially the popular ones operating as MaaS, is their stealth and evasion. Some infostealers, such as LummaStealer, use techniques like process hollowing and process injection. These techniques involve putting malicious code into an existing, trusted process, avoiding detection. Users on the device will not be able to detect infostealer activity easily, without knowing what to look for. Many infostealers have basic anti-analysis functionality, can detect antivirus, sandboxing, or use of VMs, and will terminate themselves if signs point to them being analyzed. AuraStealer, which will be discussed later, gives the user a prompt before continuing, which is likely meant to combat automated analysis. Figure 1, Screenshot of prompt box asking user to enter a randomized string (pxDpRf) to continue. Infostealers can delete themselves when finished, or will delete themselves upon detection of analysis tools and environments. During the past few months, the threat research team at ReversingLabs has been investigating and reporting on various infostealers. Focus was put on families with significant recent activity, and researchers delved specifically into features of active strains. The following is a summary of the research into three specific families, AuraStealer, ACRStealer/Amatera, and Remus Stealer. This trio of infostealers was specifically selected due to the recency of development and amount of use. ReversingLabs databases show that between June 1st and August 18th, AuraStealer had 26 samples submitted, ACRStealer had 397 (with an additional 81 for the related Amatera family) and Remus Stealer was the most prevalent with 606. Each of these counts are for unique executable samples that were submitted for the first time during the time frame. Figure 2, A graph visualizing malware activity timeline for RemusStealer (red), AuraStealer (pink), ACRStealer (cyan), from June 1 to August 20 (Generated by Spectra Intelligence MCP). AuraStealer and Remus Stealer are also newer families, having existed for less than a year, and don’t have as much data about them. The three are known for their ability to gather credentials from browsers and crypto wallets. All three are also tied to CIS countries and Russian language hacking forms, although there was no evidence found of direct relationships between the authors of these strains. They’re used in a variety of social engineering schemes, showing the vast array of potential attackers using these services. AuraStealer is a relatively new player, emerging in July of 2025. It has gained significant momentum since. It is comparable to other infostealers, and while it doesn’t directly rip off any code, it functions similarly to its direct competitors. It seems to be positioning itself to overtake the niches of other popular infostealers, like its most direct competitor and comparison point, LummaStealer. In fact, many LummaStealer detections flag AuraStealer incorrectly, at least initially. It operated as a subscription model, with basic and premium tiers, which are charged on a monthly or yearly basis. In practice, AuraStealer is used in a variety of attacks. Popular distribution methods leverage ClickFix and malicious short form videos. Researchers discovered that AuraStealer had a major transformation in summer of 2026 and this change brought virtualization. These virtualized files were directly observed by researchers at ReversingLabs. Virtualization is a technique that involves running custom commands through a virtual machine, which obfuscates and makes it harder to analyze. This change also immensely increased the filesize, bringing it from 500-700KB to 10MB. ACRStealer is an interesting case. It’s been around for a while, starting out initially in 2018. From there, it acted as a low level infostealer, not earning much success. In 2022, they rebranded and significantly upgraded the malware. It went on for two years, but in the middle of 2024, the maintainers announced an indefinite hiatus. This hiatus would involve the continuation of ongoing subscriptions, but halted the process of onboarding any new affiliates. A few months after this announcement, a new malware emerged, labeling itself as Amatera. A specific management portal for Amatera was found, and the samples associated with the panel and the Amatera name were very similar to ACRStealer. Despite the distinction in name, the two families are very similar, and it is difficult to discern what differentiates the two. Both families are in use to this day. Remus Stealer is the newest MaaS out of the three, having started at the very beginning of 2026. The first signs of Remus were in January and February, but researchers quickly caught onto it. What makes it compelling is the fact it seems to be a 64-bit variant of one of the most notorious infostealers: LummaStealer. LummaStealer is a flagship infostealer MaaS, maintaining prevalence even after a government raid of its infrastructure and the doxing of some of its key players. This comparison is drawn because Remus borrows a lot of Lumma’s traits, such as handling of string obfuscation, approach to application bound encryption (ABE) override, and design of control panels. Remus is unique for utilizing Etherhiding as a C2 communication method, a trait which Lumma does not have. Etherhiding uses Ethereum smart contracts to communicate their C2 domains, which is harder to detect, trace and block. The name “Remus” is derived from log identification strings in the code, and Lumma samples utilize a similar nomenclature with their own logs. Reports emphasize Remus’s use in malvertising, SEO-poisoning and search redirection. It is also regularly used in ClickFix, fake reaCAPCTHA, and fake downloads. One particular campaign involved Traffic Distribution System (TDS) to make fake, malicious websites reach the top of Google search results for software related terms. These webpages would redirect into a Remus payload. Frequent organizational targets of Remus include healthcare, financial, government, MSPs, and tech, but it is also used in campaigns targeting individuals, especially through gaming communities. Currently, multiple loaders (Ameday, Gcleaner and OffLoader) are dropping Remus, and these samples utilize VMProtect or a Go-based delivery stage. These families are delivered in a variety of ways. Being aware of potential vectors is a crucial step in staying safe. Social engineering is the typical means of getting MaaS onto victim devices. ClickFix and ClearFake are two popular methods attackers use to get victims to install malware. ClickFix is a social engineering technique designed to get a potential victim to run malicious commands on their own device. This typically occurs through malicious tech advice or fake reCAPTCHA verification. This technique is increasingly being seen on social media videos. ClearFake is a related technique, and has been consistently topping threat charts as something to look out for. Leveraging Javascript, ClearFake campaigns are able to automate the process, either automatically putting the malicious command into the clipboard, or retrieving or running the malicious command upon interaction. Another frequently leveraged technique is SEO poisoning. It is mentioned regularly with Remus Stealer, but other families also leverage it. The technique involves designing malicious sites that appear at the top of search results, above legitimately relevant sites, to direct traffic to malicious sites. Popular software and open source tools can be used as impersonation targets for these kinds of attacks. These are just a few examples of potential social engineering techniques, showing why it is important to stay cautious and skeptical when using the internet. Infostealers are all too common nowadays, especially considering how dangerous they are. Once downloaded, they exfiltrate many kinds of data, giving the attackers access to user information, login credentials, session tokens, crypto wallets, and more. Since they have such clear ways to generate revenue, they are appealing to threat actors, driving demand in the MaaS market and encouraging malware authors to innovate in the space and improve their products. AuraStealer, ACRStealer, and Remus Stealer are prime examples of active MaaS families. Each of them is unique in their own way, and sees different patterns of use. Being aware of different infostealer families is crucial to maintaining a safe environment. In addition, being wary of phishing schemes commonly associated with infostealer downloads is another way to prevent their installation. Observed July 2026 5b5434cc8bb3556075c6967d2ffee5a6b33793de07b9d4701bc63d369de63861 bfad1100bc3054dd26151c7acea412960ece04c3aa075ba323c10cf75c31a9a4 b8663c9c2832b92095660d1c674835acb12804e56839451e6ad9e78ed3c6d5df 134ab4b33ab555f3a77d43e94891698834a9b739b065764a702c7c52e3f4c15b a6382ab6244d3d36036280e1ec3e438f442759b6917e6bc19bcb29f1d3d7e9ee 3575caf8bd87912689ebb1d13770990248f93c5d882db8c849bee02cb7c0abad 93389f4234f81358fa29c65473b5bfc3c60ab7b3c2189185988f03a66aeda66f 01718933eb502e4ec9d4b1210a88cb026882d615605dd8d7fbf1c4057b7c0867 397566a51d405c351e5134650463d5872e218682f7f34a5f314539d087837ea4 3efc1f87e3f0566daef895ddccf21dff9eb70fbea17ec7d60ba7fdceb35c1b5c 36cfccc84b21d9bb8b3eb93589870aea0b146fd9ba649b785d44bb8dafd82656 758769a19ce049454101441e8d9e29b02c13a62146a43fa7b5692cff09ddf302 6530b7c8d9c8a48d16c94670cc9755f09b0d09efa92d65fbd1f9c7ebadce6630 c805579d25000e5270305c926dee6fcc108efede9195c2bb442a6662ddaca995 9e77a7733be97f17a64c949ef061c9fe5b23ebf3b8a171cad8f4f094ecf62fc8 730e9e0bd0a41438d7d7af227f1441b4f9d8a54988e0add3a2e0fbd7312cc163 http[:]//91.92.242[.]236/files-129312398/files/file_03e1dd22b8ec149f.exe http[:]//91.92.241[.]243/files/file_391c1e83ac309020.exe http[:]//85.239.147[.]6/files/Leetootoo/random.exe http[:]//85.239.147[.]6/files/5851730241/IQEr4wy.exe http[:]//158.94.208[.]7/files/8705834433/8njNDcy.exe http[:]//158.94.211[.]222/files/1660459253/W3Trdgs.exe http[:]//158.94.211[.]222/files/bur/fast.exe aimemtools[.]cfd softwareguard[.]cfd zkevopenanu[.]cfd dev-tools[.]cfd sys-tools[.]cfd aewaterdelivery[.]com secupd[.]cfd memaiagent[.]cfd c4831ec2b68c576199245eb877e83f9b5e83dd3f c4831ec2b68c576199245eb877e83f9b5e83dd3f 1c24da264bce471366156b4721bacb83201ba759 7c0f669cd06e5ba8fdcdba107b9519fe73519368 Observed July 2026 Packed 0843ddfbe1908c5151495295ff7d1007b3c8bca287a766c437cea6b0e3f72f4d e96c774b2c8425ab237b0fb36f57a7d8cc7e782b6d4e9a99434f3d21c93d5128 1019d8a20bd7732b2c2747b30646a5d10725fd5ee532b5e858dab27ba150db1e 06f6a0dc417bf0c8d1fa54754f53d37d190a3b9bf66658e00a630ae0bb56dfab eecf2b15c3656275f7f4d4e1e4287fee795cb857790ca7eca107efa9cd6fad30 2ab248b392653566fe4fb34e2ced50acd8e91941010f38e2a85c792968261f20 69d4b349416a93227b332b50a0d6aa38ec522d528f31f4400f248b247fd607e3 f698f7919b026700cc2a2a9166258b8770ab9412122207f7b955fb97d249b8b9 41b3e4f80aa2deeaf56c5181cd3fc1b2ee545d053d29934408bb17ddd7ea2096 Unpacked d7979fb0377c30a5361cd3f2f934c1e058a5c86031792dc66eeb24d6d7569661 4332227474b0d7db91a1e156ac3afa58ea4973ff00cb455dfd073fa1ec6dabcd 69a11394f6ee9d2af144f57d47632806f0760d5f1bdb69310a000b436ee3b5bc 9d02336c331bd335887c04ee466be41bc1a2a7e9069a9e9aaca2765484af0f14 b3708f27ddaebb5f2f256416e5082de39dd48d2a9b2bf0e9076794c3c4ca8506 aa1f23f90cd08417a86783f9c0f80c31cc621e852091f2e7ad724b89f74f11c8 510ce9e01292433f1e1163abb6a8896e3ebb2269a0489fa91a1dec7d54fec5c9 21c11f37cbf8365d26d243515cd23e822ecfa1d25f3262b62ffb1085efd09d9c 242871749873401e97d2651c5bc1c874ae9a3832a1c14b48630390dff0acafc0 9d93afbd9c5718fe14d9f24a080e8debc6b83f6596babe0aad1b3a9cb5013d01 0fac8922b1afc82d02b7a2d059ec6964a0b29196166b1377d165c08e134400db c45357593df7614af68592c0f1ef578f824dc6c9d82f7a6198b21be7c06a57d6 900b639b26e321b308ecff93998ee33637bde2a9e198b42208ab70ff9dabe35e e37280893d138dcc18a14ae4f5e4a13d71419da82ba978d7dcad510af95e86aa 2abb2d9250e78af3b0636a83f6031a14512d7d891e34a043cafc771f2ac3ea12 167873a847a2b996bd3b44b38c819768274efda6daf2978532c7b6b4f1a0acb1 127bfec23f77b6c9f2addd7f1fe8016b41078c8dbdda34737f7cb6b5563ec22b 4a3cf2cd75d78359f4ee1bc64703864781ffd8b93145c58a82078342b8097cef 641bcdaec2580058bfcbf8415ae123c7d9907c688cb107df79e20024e3bc23e2 ecde41aae4e4477a62781afdaa25c3020af8ff03008cc75e6fa0d140428abb63 252ad5844e88d5e3da533f8d913442cdc72d018ed29594a994e19a403026aa0d 377e1b540fd76b28638231ca69f955130768ea9de045e6af18b6e5b88e59211d 4c35c4ca7a9c5170587e4e8f0100f3730082e2a872e74129e38f26d3107e7e0c 8049545b6d7e2ae529a6c754c555164a79b4ebe90da7c56155c9a4282c01304d e2c92e4a8d22fc18a4e7510fc7ea4a207be80c5028bdc25f2aa06f7aa21627db a683c423efa53f048b26c3b1c530e2598d7b55833fbe3b198cd5f13a9986fb42 aaf61581328f2df00b47971c2b3882122ab7e52416dc4ac2a9637ea8255810f7 3fa65bbadec7e0d448b4d167ac48399f1f9a0966d5574b25876169171a204aba bce365972cd411ba22eb09d29792d6bb52dc485be9552a45200502e168d733b5 47a7a38d8e7d729aa0d9312fae2ebd13b7c11a5ae91474a883b7ceb56298f395 86e69bc51a02e619fcae64815445b5d8232d38361d3b055677687621e9b29c7a dd412434f9fb3d06b009c6e793938e88ab7edf71bf3180753edbcc5f1702f18e e6a771b99ea4fa87af203a786608d3f7396d1698f43242905a66e6f9539df60e 5ce36e61c71aa43b274142d8be1cb6e38d4ed52336d7b76d06a761534c0da8c4 c42849a90763133a57b4e543a4af231837e54835d3ba9a5cd9130b9d66ea3bae gw.portallbridge[.]cc login.metricsdashboard[.]cc static.quorashift[.]cc data.nomadhive[.]cc auth.automationportal[.]cc wss.vectorplatform[.]cc edge.kernelmonitor[.]cc stream.pawpalace[.]cc res.explicittweak[.]cc Observed August 2026 28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb 450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd 000b7533d53d0feed7cd995043a4298fe2b8c5767c1ffff7710f446c682928cb 2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be 48b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e 608057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da8 6f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f 55fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d1 47d5a5ef1afe3d1b8dbfde026a80d97ed0e012c144fa3940bb39758de75ca842 67cd5f1b19d33786a9f73b630357cce0d90d6771590ccb965fb331ffc6d4fb94 9935b9d36e8b6ac544a9a990bcccda8eb346596fbbcb5259bc929835b737c4d2 7e1e424f3c184c3c037235494158be38a9e7b15e0bd4a97c7f854ab03a1f09ed 84b8ec2f3b29a10f88d21fc7617cdfecac1c2c76303086b41471beb5f563f65c 99830a24d6aed654adff341b2c6ad2ba6c971c028dfce1ca455a37d1fbdf4617 ab8cee7ddbeb8d937f8a6855c52cee704bb6f4a10934fcaf17544a8c31cced39 b7c682fc6e8ea93f44c2c86fcd06e664971f42e8290a534c65a32a92d9b53a14 b40cb47ab1775a4be4ec9b997b58bedfeb2076079df0804dc80982c0309fa9a2 c1e0d2c9e04fcdb10ff2d4565758ceda1331fc80def548742a79b60be81da9b9 d3b08fd3ce1ca451b1dffd00c657b6ac1ad8ad769171faa1ba9688b572283d32 cd7c5860e0e6bdbc49ae5f07d85989469a41a108dede6f6086541d276ccc155f e99d9294331c15c7ee0f4a03f8b95eda42fa065ec7d008bc326f9d8db562c118 de0d703c69ec8421a5351dc02735179aee12e8257b5816108feda8716b695b49 dbd1aae6e2a47af68e987dbfcc91c564d17c532e892938983eac8f891dec81b9 f68ba32766e087f5a6855fa7da9feea2968280a019aec31d7d173adcd4b848ca f3ef2636d9b60715c2ea7c032cfd20492b7701bfa72ed3652b2bc540760988a0 fc8a7102ed41830084bcd7c4176a93366ad3c9ce0662cb006f15f01f763cb260 28d1f5d695ed65461b36f032f057a2d48b97ea68f149c73ea3401bf9ec0576cb 450216a711f8b3371a2936923201f204fa1c686a2b831dac4a1c0094c105a5fd 000b7533d53d0feed7cd995043a4298fe2b8c5767c1ffff7710f446c682928cb 2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be 48b82c79a90ed401449260948b269d0909bbdb53847678dfbba09c368016bd7e 608057bea6ee1cc68c1f1bdcbe702a3558270d8f19cc329b8b34bcd133984da8 6f737981ac722be8ae1c05a295667d050abe1b45dd946e1dbf4c46467c517c5f 55fd126063af89eb1c5639a56dcf365f2e817813a45758b3f12a18f12d5561d1 47d5a5ef1afe3d1b8dbfde026a80d97ed0e012c144fa3940bb39758de75ca842 URLs hxxp[://]azurhay[.]shop:8539 hxxp[://]carogra[.]biz:4219 hxxp[://]fimmora[.]surf:6504 hxxp[://]freshis[.]biz:7752 hxxp[://]hooiuse[.]click:4938 hxxp[://]myrtler[.]biz:9549 hxxp[://]onesdto[.]shop:2535 hxxp[://]slyfogx[.]shop:5776 hxxp[://]topxgax[.]click:4930 hxxp[://]tzpx[.]courses:4437 hxxp[://]uiccvbk[.]click:8839 hxxp[://]youngel[.]biz:8768 hxxp[://]zelpx[.]garden:9895 Domains azurhay[.]shop carogra[.]biz fimmora[.]surf freshis[.]biz hooiuse[.]click myrtler[.]biz onesdto[.]shop slyfogx[.]shop topxgax[.]click tzpx[.]courses uiccvbk[.]click youngel[.]biz zelpx[.]garden SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work. One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.