Executive Summary
REVSTEALER is an emerging commercial infostealer (identified under REF2859) that targets browser credentials, gaming accounts, and cryptocurrency wallets. The malware is notable for its sophisticated anti-analysis techniques, including a 10-tier sandbox scoring system and the use of indirect syscalls to bypass EDR hooks. It utilizes a resilient 'EtherHiding' mechanism, where Polygon blockchain smart contracts serve as dead-drop resolvers for C2 configuration if primary servers are unreachable.
The attack chain often begins with social engineering via hijacked YouTube channels advertising game cheats. Beyond the core stealer, the C2 can deliver four follow-on modules: ProManager (wallet theft/phishing), WinUpdate (clipboard clipper), SoftManager (reverse SOCKS5 proxy), and LockAppHost (privileged crypto-miner). The LockAppHost module is particularly invasive, as it actively tampers with Windows Update and Microsoft Defender to ensure persistent mining operations.
This threat poses significant financial and operational risk to individual users and organizations, particularly in the gaming and cryptocurrency sectors. The combination of credential harvesting and post-exploitation modules like reverse proxies allows for long-term unauthorized access and infrastructure exploitation.
Key Details
Threat Name
REVSTEALER
Affects
—
Adversary
REVSTEALER Other Adversaries and Aliases: REF2859
MITRE Techniques
Malware/Tools
REVSTEALER, ProManager, WinUpdate, SoftManager, LockAppHost, XMRig, Lumma Stealer, AuraStealer, LATRODECTUS, VoidStealer
