June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading — Threadlinqs Intelligence
As of 2026-07-15, June 2026 Infostealer Campaign Trends: Remus, ACRStealer, LummaC2, Vidar Distributed via SEO Poisoning and DLL Sideloading is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-1353 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
ASEC's June 2026 infostealer trend report identifies Remus, ACRStealer, LummaC2, and Vidar as the dominant infostealer variants in circulation, distributed via SEO-poisoned search results and
AhnLab's ASEC published its June 2026 infostealer trend report identifying Remus, ACRStealer, LummaC2, and Vidar as the four dominant credential-stealing malware families observed in circulation that month. Distribution overwhelmingly relied on SEO poisoning of search results for cracked software and keygens, driving victims to file-sharing services such as Mediafire and Mega that host trojanized installers. 84.5% of collected samples were straightforward EXE droppers, while roughly 15.5% relied on DLL sideloading using hijacked DLL names (python37.dll, LcMgr.dll, python315.dll), and Microsoft Corporation was the most frequently spoofed code-signing identity across samples.
Remus is a 64-bit Malware-as-a-Service infostealer forked directly from Lumma Stealer's source code following the doxxing of Lumma's core developers between August and October 2025. It shares Lumma's anti-VM CPUID hypervisor checks (KVM, QEMU/TCG, VMware, VirtualBox, Xen) and sandbox-DLL detection via CRC32-hashed PEB module walks, but replaces Lumma's ROT-15 dead-drop resolvers with 'EtherHiding' — resolving live C2 domains via eth_call JSON-RPC requests against hardcoded Ethereum/Polygon smart contracts, an approach researchers describe as effectively immune to conventional takedown. Remus steals browser passwords, cookies, session tokens (enabling MFA bypass via active session theft), cryptocurrency wallets, Discord tokens, and clipboard contents, and injects into browser processes to defeat Chrome's App-Bound Encryption, falling back to SYSTEM token impersonation on injection failure.
ACRStealer is distributed via HijackLoader-based installers hosted on Mediafire, AWS S3, and Mega, often via the pivigames[.]blog redirector, and impersonates Ren'Py game packages. It performs syscall-level EDR evasion (NTCalls/WoW64 abuse, manual NTDLL Export Address Table parsing via modified djb2 hashing), bypasses Chrome App-Bound Encryption for versions prior to 127, and specifically targets Steam credential files (loginuser.vdf, local.vdf) alongside Discord and Twitch session data.
LummaC2, a long-running MaaS stealer, continues browser/crypto-wallet theft via fake-CAPTCHA (ClickFix) lures that trick victims into pasting and executing a hidden PowerShell command, and maintains tiered C2 infrastructure (hardcoded .shop-TLD tier-1 domains behind Cloudflare, with Steam-profile and Telegram-channel fallback resolvers) despite a May 2025 Microsoft/Europol-led takedown.
Vidar Stealer campaigns observed through April 2026 pair Go-based Factory-v3 loaders — all discovered samples share a Go 1.25.9 build fingerprint — with forged Authenticode signatures impersonating JustWatch GmbH and BleacherReport, DLL side-loading of Windows Defender's MpClient.dll export surface, and co-bundled XMRig cryptomining, POSTing stolen data to bare-IP C2 panels over HTTPS.
A parallel and increasingly prominent macOS-targeted vector, ClickFix, compromises WordPress sites to serve fake CAPTCHA/system-utility prompts that trick victims into pasting Terminal/Bash commands, delivering infostealers (Macsync, Shub Stealer, AMOS) and establishing LaunchAgent persistence. Since March 2026, this campaign (tracked by Unit 42 as an 'Aeternum'-style operation) has rotated C2 domains roughly every 22 hours via a single Polygon smart contract's getURL() function queried over public eth_call RPC endpoints, blending malicious lookups into legitimate Web3 traffic across 130+ compromised sites. Adjacent June activity also included AgentTesla delivered via Japanese materials-company impersonation and DarkCloud via Indian electronics-manufacturer impersonation, both using compressed email attachments with SMTP-based exfiltration.
Target sectors: individual consumers, gaming, cryptocurrency, technology, financial services
Target regions: Global, south korea, united states of america, germany, mongolia, australia, European Union
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1608.006, T1584, T1204.002, T1059.001, T1059.004, T1547.001, T1134.003, T1574.002, T1036.001, T1027