typeentityconfidencelowcreated2026-08-19updated2026-08-19infostealermalware-familygolangcontested

remusstealer

OpenCTI umbrella label applied to a cluster of Go-compiled Windows infostealers. Static analysis of corpus samples bearing this tag resolves to the acrstealer cluster by shared certificate chain (GlobalSign Atlas R3 DV TLS CA 2025 Q4 → seekingalpha.com) and Go build fingerprint (GOARCH=amd64, GOOS=windows, CGO_ENABLED=0, -trimpath=true).

Contested Status

This label is treated as a low-confidence contested umbrella — no independent technical fingerprint separates it from the ACR cluster. Every remusstealer-tagged sample analysed in this corpus has been re-attributed to acrstealer via:

  • Certificate chain match (seekingalpha.com, atom.hutsell.com/WR3, quiverquant.com/WE1)
  • Go build ID / module path randomization pattern
  • Randomized main.* function name count (11–92)
  • .rsrc icon suite presence/absence (builder toggle)

Observed Samples

SHA Prefix OpenCTI Label Resolved Family Evidence
ea41d4b1 remusstealer acrstealer Go 1.20.6, seekingalpha.com cert, 81 main.* ^[/intel/analyses/ea41d4b15a8e270f2113b16f050cb3e15cb5a5c85711fb6ec31dc6bb7279ba42.html]

Capabilities

See acrstealer for the authoritative capability list. This stub exists only to prevent orphaned [remusstealer](/intel/families/remusstealer.html) wikilinks from prior OpenCTI triage labels.

Related