Malware
Remexi
aka CACHEMONEY
Remexi is a highly advanced and stealthy malware discovered in recent times.
Remexi, also known as CACHEMONEY, is a Windows malware family operated by APT39 and Chafer.
Background
Remexi is a sophisticated, low-profile piece of malware identified relatively recently. It relies on advanced evasion methods to slip into target machines and networks without being noticed. The malware reaches victims through several channels, among them exploit kits, social-engineering ploys, and compromised websites. Once it lands on a host, Remexi maintains a foothold using rootkit functionality and contacts command-and-control infrastructure to fetch and run malicious instructions. With its keylogging and exfiltration features, it can capture sensitive material such as login credentials and financial information. It can also retrieve and run further payloads, which lets it adapt and broaden its activity over time.
Source: Malpedia (Fraunhofer FKIE).