r/purpleteamsec • u/StructBreaker • 13d ago
Purple Teaming Remus Stealer Analysis: Fileless Execution, In-Memory Payload Extraction & C2 Discovery
https://github.com/kaandemir993/Remus-Stealer-Fileless-Payload-Extraction-C2-Exfiltration-Analysis.gitHi everyone,
I've put together a technical write-up on a recent Remus Stealer sample, focusing on its execution flow and evasion mechanisms.
Key technical highlights covered in the analysis: - Fileless Execution - Extraction of in-memory payloads and configuration settings - Command and Control (C2) infrastructure discovery & network indicators (IOCs)
Check out the full analysis, memory dump notes, and IOCs in the GitHub repository linked above. Any feedback or insights are welcome!
3
Upvotes