Malicious RemusStealer Credential Exfiltration to pics TLD C2

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-09-09
Updated
2026-09-09

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects HTTP POST requests to hosts under the .pics top-level domain whose body carries access_token and step parameters, the exfiltration pattern of RemusStealer distributed by this ecosystem. This structured upload to an uncommon TLD signals active credential and session-token theft.

Related detections9 linkedT1555.003 — drag to rearrange
Suspicious Access to Chrome Login Data on macOS (via process_creation)
Suspicious Access To Chrome Credential Files
Windows SQLite CLI Querying Chromium Browser Profile Databases
Suspicious Local Password Validation via dscl authonly
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Malicious Fake Fortinet Patch Infostealer Execution (via process_creation)
Suspicious BoryptGrab Infostealer Staging Directory (via file_event)
Malicious Interlock Credential Stealer Output File
Malicious Browser Master Key Decryption Artifacts Written by Katz Stealer (via file_event)
Malicious RemusStealer Credential Exfiltration to pics TLD C2
Pivot detection · T1555.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.