REVSTEALER Infostealer Ramps Up With Follow-on Modules
Score: 9/10

REVSTEALER Infostealer Ramps Up With Follow-on Modules

REVSTEALER is a feature-rich Windows infostealer targeting browsers, gaming platforms, and cryptocurrency wallets, often deploying secondary modules for persistent theft and mining.

Executive Summary

REVSTEALER (tracked as REF2859) has emerged as a sophisticated commercially distributed infostealer primarily targeting gaming enthusiasts and cryptocurrency users. Distributed through social engineering lures like fake game cheats and trojanized AI software (e.g., "Claude Opus 5 Free Desktop"), the malware employs advanced evasion techniques including indirect syscalls, custom exception handling, and a 10-tier sandbox scoring system to thwart analysis.

Notably, REVSTEALER utilizes 'EtherHiding,' a technique involving the retrieval of backup Command and Control (C2) configurations from Polygon blockchain smart contracts. While the core stealer is designed for short-burst execution and self-deletion, it often delivers persistent follow-on modules—ProManager, WinUpdate, SoftManager, and LockAppHost—which extend operational longevity through reverse proxies, clipboard manipulation, and privileged cryptocurrency mining.

Key Details

Threat Name

REVSTEALER

Affects

—

Adversary

REVSTEALER Other Adversaries and Aliases: REF2859

Malware/Tools

REVSTEALER, ProManager, WinUpdate, SoftManager, LockAppHost, XMRig, Lumma Stealer, AuraStealer, LATRODECTUS, VoidStealer

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details10
Detection Guidance8
Enterprise Relevance9
Clarity & Structure9
Technical Depth10

Sources