Back to Intelligence

RemusStealer EtherHiding C2, StreamRat Banking Trojan & PamStealer macOS Campaign: OTX Pulse Analysis — Infostealer Detection Pack

SA
Security Arsenal Team
October 2, 2026
10 min read

Five OTX pulses published this cycle collectively paint a picture of a maturing infostealer-as-a-service economy that has moved well beyond commodity password theft. The dominant themes across this batch:

  1. Blockchain-resilient C2 is going mainstream. RemusStealer — a LummaStealer lookalike written in Go — abandons traditional dead-drop resolvers (Steam, Telegram) in favor of Ethereum smart contracts ('EtherHiding') to store and resolve C2 configuration. This defeats domain takedowns and DNS-layer blocking, since the configuration lives on an immutable public ledger.

  2. Mobile banking fraud at industrial scale. StreamRat, distributed via Meta and TikTok ads masquerading as a free TV-streaming app, reached ~570,000 potential victims in Spain. It chains Accessibility Services abuse with MediaProjection-based VNC streaming for full device takeover, sitting alongside the Mirax, GodFather, and Sturnus families in the Android MaaS ecosystem.

  3. Cross-platform expansion. The PamStealer variant targets macOS through a fake 'Wavel' cryptocurrency wallet, using a novel server-side ECIES decryption chain (via a custom pkgunpack utility) that makes offline payload analysis impossible. Meanwhile the 'Underground' operation's Aotera/Tedy loader injects Vidar-class stealers into browser sessions and has drained ~$100,000 in crypto across 23 blockchains via clipboard clipping and browser injection.

  4. State-aligned activity in parallel. Kimsuky continues spear-phishing South Korean entities with LNK files, PowerShell, AutoIt, and DLL side-loading, deploying XenoRAT and using PubNub as a C2 channel.

Collective objective: credential harvesting at scale — browser credentials, session cookies, crypto wallets, Keychain data (macOS), and banking credentials (Android) — monetized through crypto draining, account takeover, and resale on dark web credential markets.

Threat Actor / Malware Profile

RemusStealer (MaaS, LummaStealer lineage)

  • Distribution: Malware-as-a-service; delivery vectors mirror Lumma (malvertising, fake updates, cracked software).
  • Payload behavior: Written in Go; steals browser credentials, cookies, and crypto wallet data; bypasses Chromium Application-Bound Encryption (ABE); performs extensive system fingerprinting.
  • C2: Ethereum smart contracts act as a configuration dead-drop — the malware queries the blockchain to resolve live C2 infrastructure. Observed C2 domain: shivlpf.shop.
  • Anti-analysis: Anti-VM checks, execution on hidden Windows desktops to evade user and sandbox observation.

StreamRat (Android banking trojan)

  • Distribution: Meta and TikTok advertisements promoting a fake free TV-streaming app targeting Spanish-speaking users; two-stage install with a dropper that blocks internet access during installation to defeat Play Protect / network inspection.
  • Payload behavior: Accessibility Services abuse for overlay injection and permission self-granting; MediaProjection-based VNC for real-time device takeover; banking credential theft targeting Spanish financial institutions.
  • C2: VNC streaming channel plus panel communication over encrypted HTTP.

Aotera/Tedy Loader + Vidar-class Stealer ('Underground' operation)

  • Active since: October 2023.
  • Payload behavior: Loader injects stealer into Windows processes; launches Chrome/Edge and injects malicious scripts into live sessions; clipboard clipper swaps copied crypto addresses; ~$100k drained across 80+ destination addresses on 23 blockchains.
  • C2: Seven gate domains; telemetry/beaconing to 95.164.53.76 with structured URL paths (/new/log/<ID>/startLoader, /success, /failed) that double as a victim-tracking state machine.

Kimsuky (DPRK-nexus APT)

  • Distribution: Spear phishing with malicious LNK files; six distinct attack chains identified in August 2026 targeting South Korea.
  • Payload behavior: PowerShell and AutoIt staging, DLL side-loading, HEX-encoded data extraction; PubNub abused as C2 channel; curl.exe used to pull HTA second stages; final payload XenoRAT.
  • Infrastructure: www.cwmodern.com, www.dolgicap.com.

PamStealer v3 (macOS)

  • Distribution: Fake 'Wavel' cryptocurrency wallet DMG (y32me8.com/Wavel.dmg).
  • Payload behavior: Steals Keychain contents, browser credentials, and crypto wallets; performs PAM validation to verify harvested passwords; rewritten second stage (from Rust lineage); establishes persistence.
  • C2: Live ECIES key exchange with C2 via purpose-built pkgunpack utility; payloads delivered encrypted (CoreUpdate.pkg.enc) and decrypted server-side, defeating offline reverse engineering.

IOC Analysis

The indicator set spans four operationalization tiers:

  • File hashes (SHA256/MD5): StreamRat APKs, PamStealer DMG/payloads, and Kimsuky LNK/stager samples. Push SHA256 values into EDR blocklists immediately. MD5s from the ASEC report are useful for retrospective hunting in mail gateways and download caches. Note that MaaS operators recompile frequently — hashes decay in value within days; treat them as point-in-time artifacts, not durable controls.
  • Domains/hostnames: shivlpf.shop (RemusStealer), y32me8.com, wavel.apple03cloudstore.com (PamStealer), quick-neo.com (Underground gate), www.cwmodern.com, www.dolgicap.com (Kimsuky). Sinkhole at the DNS resolver and alert on historical resolution via passive DNS. The apple03cloudstore.com subdomain pattern is typosquat-style brand impersonation — flag similar lookalikes in newly-registered-domain feeds.
  • IPv4: 95.164.53.76 — hardcoded Underground C2. Block egress at the perimeter and hunt proxy/firewall logs retroactively 90 days.
  • URLs: The Underground panel URLs (/new/log/<victim-id>/<state>/<timestamp>) are the highest-fidelity detections in this batch. The structured path schema (startLoader, startCrypt, success, failed) is a behavioral signature — write proxy detections for the regex /new/log/[0-9A-Fa-f]{8}/(startLoader|startCrypt|success|failed)/ rather than relying solely on the IP. PamStealer's /v1/asset/ and /pkgunpack paths similarly signature-ize well.

Tooling: Normalize indicators into STIX/TAXII for SIEM ingestion; use OTX DirectConnect or the OTXv2 API to pull full pulse IOC sets; decode Chromium ABE-protected artifacts in sandboxes (ANY.RUN, Triage) since RemusStealer/Vidar specifically target ABE bypass; for the Ethereum C2, monitor contract interaction rather than network egress alone.

Detection Engineering

YAML
---
title: RemusStealer / Underground Loader C2 Telemetry Pattern
id: 7f2a1c4e-9b3d-4e5a-a1c2-8d6f0b2e4a91
status: experimental
description: Detects HTTP beaconing matching the Underground operation's structured victim-telemetry URI schema and RemusStealer gate domain contact
author: Security Arsenal
references:
  - https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation
  - https://binarydefense.com/resources/blog/remusstealer-etherhiding-in-hidden-windows
date: 2026/10/02
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.t1567
logsource:
  category: proxy
detection:
  selection_uri:
    c-uri|contains: '/new/log/'
  selection_state:
    c-uri|contains:
      - '/startLoader'
      - '/startCrypt'
      - '/success/'
      - '/failed/'
  selection_domain:
    cs-host:
      - 'shivlpf.shop'
      - 'quick-neo.com'
  condition: (selection_uri and selection_state) or selection_domain
falsepositives:
  - Unlikely; URI schema is operationally distinctive
level: high
---
title: Chromium Browser Launched by Non-User Process for Script Injection
id: 2b8d5f1a-3c4e-4a6b-9d7c-1e5f8a0b3c62
status: experimental
description: Detects Chrome/Edge spawned by uncommon parent processes, consistent with Vidar-class stealer browser session injection
author: Security Arsenal
references:
  - https://www.netskope.com/blog/100k-in-crypto-drained-by-the-underground-operation
date: 2026/10/02
tags:
  - attack.credential_access
  - attack.t1555.003
  - attack.t1055
logsource:
  category: process_creation
  product: windows
detection:
  selection_browser:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
  selection_suspicious_parents:
    ParentImage|endswith:
      - '\rundll32.exe'
      - '\regsvr32.exe'
      - '\powershell.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\mshta.exe'
      - '\cmd.exe'
  condition: selection_browser and selection_suspicious_parents
falsepositives:
  - Enterprise software deployment tools launching browsers
  - Helpdesk scripts opening URLs
level: medium
---
title: LNK File Execution with PowerShell or Curl Download - Kimsuky Pattern
id: 4c9e2a7b-1d5f-4b8c-a3e6-9f0d2c5b7a14
status: experimental
description: Detects Kimsuky-style spear-phish chain - LNK files invoking PowerShell, curl.exe HTA downloads, or mshta execution of remote content
author: Security Arsenal
references:
  - https://asec.ahnlab.com/en/95649
date: 2026/10/02
tags:
  - attack.initial_access
  - attack.t1566.001
  - attack.t1204.002
  - attack.t1218.005
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent_lnk:
    CommandLine|contains:
      - '.lnk'
  selection_download:
    CommandLine|contains:
      - 'curl.exe'
      - 'curl '
      - '.hta'
      - 'mshta http'
      - 'pubnub'
  condition: selection_parent_lnk or (selection_download and selection_parent_lnk)
falsepositives:
  - Rare legitimate LNK shortcuts invoking scripts; baseline per environment
level: high
KQL — Microsoft Sentinel / Defender
// Security Arsenal - Multi-Family Infostealer Hunt (OTX 2026-10-02)
// Hunts: Underground C2 telemetry, RemusStealer/PamStealer domains, browser injection parents
let iocDomains = dynamic(["shivlpf.shop", "quick-neo.com", "y32me8.com", "apple03cloudstore.com", "www.cwmodern.com", "www.dolgicap.com"]);
let iocIPs = dynamic(["95.164.53.76"]);
let networkHits = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (iocDomains) or RemoteIP in (iocIPs)
    or RemoteUrl matches regex @"/new/log/[0-9A-Fa-f]{8}/(startLoader|startCrypt|success|failed)"
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, ActionType
| extend Hunt = "Network IOC";
let browserInjection = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName in~ ("chrome.exe", "msedge.exe")
| where InitiatingProcessFileName in~ ("rundll32.exe", "regsvr32.exe", "powershell.exe", "wscript.exe", "cscript.exe", "mshta.exe", "cmd.exe")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, ProcessCommandLine, AccountName
| extend Hunt = "Browser Injection Pattern";
let hashHits = DeviceFileEvents
| where TimeGenerated > ago(14d)
| where SHA256 in ("ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3",
    "e0714788b4e2518b0d9d4cbf18c7217bb97718e01689d77338f1cc4a230fcb6c",
    "484129123e8509acdc733d44e9a53c1cafa5afc1e2a28d49a55d0e209806d898",
    "be7ac520b804f933db0dc789431034eaae7b14c7ff7ff65605d736e9d5873163",
    "ed980f2fa0642b1a5ba0bca65f5b3baee8a7b3f5d149bf295aa4ac7a70b92cec")
| project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| extend Hunt = "Known Malware Hash";
union networkHits, browserInjection, hashHits
| sort by TimeGenerated desc
PowerShell
# Security Arsenal - Infostealer Artifact Hunt (OTX 2026-10-02)
# Checks network artifacts, persistence, clipboard-access anomalies, and known IOC presence
$ErrorActionPreference = 'SilentlyContinue'
$report = @()

Write-Host "[*] Checking active/historical network connections to known C2..."
$c2Targets = @('95.164.53.76', 'shivlpf.shop', 'quick-neo.com', 'y32me8.com', 'www.cwmodern.com', 'www.dolgicap.com')
foreach ($target in $c2Targets) {
    $conns = Get-NetTCPConnection | Where-Object { $_.RemoteAddress -eq $target }
    if ($conns) { $report += "[HIT] Active connection to $target by PID $($conns.OwningProcess)" }
}

Write-Host "[*] Querying DNS cache for malicious domains..."
$dnsCache = Get-DnsClientCache | Where-Object { $_.Entry -match 'shivlpf|quick-neo|y32me8|apple03cloudstore|cwmodern|dolgicap' }
if ($dnsCache) { $dnsCache | ForEach-Object { $report += "[HIT] DNS cache: $($_.Entry) -> $($_.Data)" } }

Write-Host "[*] Checking for suspicious Run-key persistence (infostealer/stealer staging)..."
$runKeys = @('HKCU:\Software\Microsoft\Windows\CurrentVersion\Run',
             'HKLM:\Software\Microsoft\Windows\CurrentVersion\Run')
foreach ($key in $runKeys) {
    $vals = Get-ItemProperty -Path $key
    foreach ($prop in $vals.PSObject.Properties) {
        if ($prop.Value -match 'AppData|Temp|ProgramData|powershell|mshta|rundll32' -and $prop.Name -notmatch '^PS') {
            $report += "[REVIEW] $key\$($prop.Name) = $($prop.Value)"
        }
    }
}

Write-Host "[*] Checking scheduled tasks executing from user-writable paths..."
Get-ScheduledTask | ForEach-Object {
    $task = $_
    $_.Actions | Where-Object { $_.Execute -match 'AppData|Temp|Public' } | ForEach-Object {
        $report += "[REVIEW] Scheduled task '$($task.TaskName)' runs $($_.Execute)"
    }
}

Write-Host "[*] Hunting Chromium credential-store access artifacts (recent Login Data copies)..."
$browserPaths = @("$env:LOCALAPPDATA\Google\Chrome\User Data", "$env:LOCALAPPDATA\Microsoft\Edge\User Data")
foreach ($bp in $browserPaths) {
    Get-ChildItem -Path $bp -Recurse -Filter 'Login Data*' | Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-3) } | ForEach-Object {
        $report += "[REVIEW] Recently modified credential store: $($_.FullName)"
    }
}

Write-Host "[*] Checking known malware hashes in common staging dirs..."
$hashes = @('ba83cc3c9535690191018edf73ca5c6001609df9919462796aa2e551f142e4d3',
            '484129123e8509acdc733d44e9a53c1cafa5afc1e2a28d49a55d0e209806d898')
Get-ChildItem -Path "$env:TEMP","$env:APPDATA","$env:USERPROFILE\Downloads" -Recurse -File -Depth 2 | ForEach-Object {
    $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
    if ($hashes -contains $h) { $report += "[HIT] Known malware file: $($_.FullName) ($h)" }
}

if ($report.Count -eq 0) { Write-Host "[+] No artifacts found." } else { $report | ForEach-Object { Write-Host $_ } }

Response Priorities

Immediate (0–4 hours)

  • Block all IOC domains/IPs at DNS resolver, web proxy, and egress firewall: shivlpf.shop, quick-neo.com, y32me8.com, apple03cloudstore.com, www.cwmodern.com, www.dolgicap.com, 95.164.53.76.
  • Push StreamRat, PamStealer, and Kimsuky file hashes into EDR blocklists.
  • Deploy the proxy regex detection for the Underground /new/log/ telemetry schema — this catches infrastructure rotation.
  • Run the KQL hunt retroactively across 14–30 days of telemetry.

24 Hours

  • Any host that communicated with C2 infrastructure or executed a flagged hash is presumed credential-compromised. Force enterprise password resets and revoke all active sessions/tokens for affected users — infostealers exfiltrate session cookies, making password-only resets insufficient.
  • Invalidate OAuth grants and refresh tokens; check for unauthorized mailbox rules and MFA enrollment changes.
  • For crypto-adjacent staff (treasury, finance), verify no wallet transactions occurred from potentially compromised hosts; treat clipboard clipper exposure as an active theft risk.
  • Mobile: audit managed Android fleets for sideloaded APKs matching StreamRat hashes; enforce Play Protect and block Accessibility Service grants to non-allowlisted apps.

1 Week

  • Architectural hardening against the delivery vectors observed: restrict LNK execution from email/download zones (mark-of-the-web enforcement); block mshta and curl for standard users via AppLocker/WDAC; restrict child processes of browsers.
  • Deploy browser credential-store protections: enable App-Bound Encryption enforcement, and consider moving high-value users to hardware-key/passkey auth to neutralize cookie-theft session hijacking.
  • macOS: deploy Jamf/MDM controls blocking unsigned DMG execution outside the App Store; alert on Keychain access by non-system binaries.
  • For blockchain-C2 resilience (RemusStealer): since DNS blocking cannot stop smart-contract resolution, prioritize behavioral detection (hidden desktop creation, anti-VM strings, ABE-bypass API sequences) over indicator blocking.
  • Feed all indicators into your TIP and subscribe to the referenced OTX pulses for ongoing updates as MaaS operators rotate infrastructure.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.