Skip to main content
Mallory
Back to stories
command-and-control-methodthreat-infrastructure-trackingcredential-stealer-activitycryptocurrency-platform-risk

Remus Infostealer Used Ethereum Smart Contracts to Rotate Live C2 Infrastructure

Updated 12d agoFirst seen Apr 28, 20264 sources

Researchers mapped an active Remus infostealer infrastructure cluster that stores live command-and-control data in Ethereum smart contracts, extending the malware's use of dead-drop resolvers beyond Telegram and Steam. By querying contract 0x999941b74F6bbc921D5174A5b29911562cd2D7CF via a public RPC endpoint and tracking its DomainUpdated activity, they identified a previously unlisted live C2 at fightwa[.]biz:5902, following earlier values including chalx[.]live:5902. Historical updates showed the operators were rotating infrastructure through late April, and the newly identified domain resolved to 185.53.179.128, an IP already linked to Remus operations.

Further analysis tied the campaign to a broader, automated infrastructure spread across more than 15 ASNs, with notable concentration at Hostinger International Limited (AS47583) and Team Internet AG (AS206834). Investigators found heavy use of .biz domains registered in early March through Dynadot, shared certificate and hosting patterns, and four additional Ethereum contracts beyond the one first identified, bringing the total to five contracts used to publish live C2 information. The contract set showed an evolution from simple DomainStorage logic to more advanced DataStore variants with stronger validation, ownership controls, and gas-optimized stealth features, while one v3 contract included a Russian-language code comment that researchers said was only a minor attribution clue consistent with the broader Remus/Lumma ecosystem.

Share:
Remus Infostealer Used Ethereum Smart Contracts to Rotate Live C2 Infrastructure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the earliest known activity through the most recent confirmed update.

7 EVENTS
Sep 1, 20259mo ago

Researchers trace Remus to September 2025 Tenzor test builds

Gen Threat Labs reported that Remus could be traced to September 2025 test builds labeled Tenzor and assessed it as a new 64-bit variant closely derived from Lumma Stealer. The analysis also highlighted inherited Chromium key-theft techniques and EtherHiding-based C2 resolution, indicating Remus evolved from the Lumma ecosystem rather than appearing suddenly in 2026.

Remus Infostealer Uses Lumma-Style Browser Key Theft and Application-Bound Encryption Bypass
Mar 1, 20263mo ago

Remus infrastructure domains registered in early March

The Remus infostealer campaign registered many .biz domains around the same time in early March 2026 through Dynadot. Shared certificate and hosting traits suggested an automated infrastructure setup.

Apr 1, 20262mo ago

Researchers find exposed xlabs_v1 botnet directory

In early April 2026, researchers discovered an exposed open directory on 176.65.139.44 and used its publicly accessible files to reconstruct the Mirai-derived xlabs_v1 DDoS-for-hire operation. The malware was found targeting internet-exposed Android Debug Bridge services on TCP/5555 and supporting multiple architectures.

Apr 25, 202623d ago

Remus Ethereum contract rotates to fightwa[.]biz:5902

Historical smart-contract activity showed the Remus cluster progressing from a test domain to chalx[.]live:5902 and then to fightwa[.]biz:5902. The latest observed C2 rotation occurred as recently as 2026-04-25, indicating the infrastructure was still active.

Apr 28, 202620d ago

Research identifies live Remus C2 via Ethereum smart contract

By querying Ethereum contract 0x999941b74F6bbc921D5174A5b29911562cd2D7CF with function selector 0xc2fb26a6 through a public RPC endpoint, a researcher identified live C2 domain fightwa[.]biz:5902. The hosting IP 185.53.179.128 matched infrastructure previously associated with Remus, supporting attribution to the same campaign.

Apr 29, 202619d ago

Researchers expose xlabs_v1 botnet infrastructure and protocol

Analysis of xlabs_v1 production and development binaries revealed 21 attack variants, a plaintext-framed C2 protocol over TCP/35342 using xlabslover[.]lol, and infrastructure concentrated in the 176.65.139.0/24 netblock in the Netherlands. Weak ChaCha20 implementation details also allowed recovery of the operator handle Tadashi, bot tag xlabs_v1, and an authentication token.

Apr 30, 202618d ago

Additional Remus smart contracts and infrastructure concentration mapped

Further analysis of the Remus campaign uncovered four additional Ethereum smart contracts beyond the previously identified one, bringing the total to five used to store live C2 information. The research also highlighted infrastructure concentration at Hostinger International Limited and Team Internet AG, with 185.53.179.128 identified as a likely central convergence or exfiltration server.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.