REVSTEALER: Sophisticated Infostealer with Polygon C2 Resilience
Score: 10/10

REVSTEALER: Sophisticated Infostealer with Polygon C2 Resilience

REVSTEALER is a comprehensive Windows infostealer using Polygon smart contracts for resilient C2 infrastructure and delivering specialized modules for crypto-mining and reverse proxying.

Executive Summary

REVSTEALER is an emerging commercial infostealer (identified under REF2859) that targets browser credentials, gaming accounts, and cryptocurrency wallets. The malware is notable for its sophisticated anti-analysis techniques, including a 10-tier sandbox scoring system and the use of indirect syscalls to bypass EDR hooks. It utilizes a resilient 'EtherHiding' mechanism, where Polygon blockchain smart contracts serve as dead-drop resolvers for C2 configuration if primary servers are unreachable.

The attack chain often begins with social engineering via hijacked YouTube channels advertising game cheats. Beyond the core stealer, the C2 can deliver four follow-on modules: ProManager (wallet theft/phishing), WinUpdate (clipboard clipper), SoftManager (reverse SOCKS5 proxy), and LockAppHost (privileged crypto-miner). The LockAppHost module is particularly invasive, as it actively tampers with Windows Update and Microsoft Defender to ensure persistent mining operations.

This threat poses significant financial and operational risk to individual users and organizations, particularly in the gaming and cryptocurrency sectors. The combination of credential harvesting and post-exploitation modules like reverse proxies allows for long-term unauthorized access and infrastructure exploitation.

Key Details

Threat Name

REVSTEALER

Affects

—

Adversary

REVSTEALER Other Adversaries and Aliases: REF2859

Malware/Tools

REVSTEALER, ProManager, WinUpdate, SoftManager, LockAppHost, XMRig, Lumma Stealer, AuraStealer, LATRODECTUS, VoidStealer

Report Score

10out of 10
Quality Score
Excellent
IOC Quality9
TTP Details10
Detection Guidance9
Enterprise Relevance9
Clarity & Structure10
Technical Depth10

Sources