Executive Summary
REVSTEALER (tracked as REF2859) has emerged as a sophisticated commercially distributed infostealer primarily targeting gaming enthusiasts and cryptocurrency users. Distributed through social engineering lures like fake game cheats and trojanized AI software (e.g., "Claude Opus 5 Free Desktop"), the malware employs advanced evasion techniques including indirect syscalls, custom exception handling, and a 10-tier sandbox scoring system to thwart analysis.
Notably, REVSTEALER utilizes 'EtherHiding,' a technique involving the retrieval of backup Command and Control (C2) configurations from Polygon blockchain smart contracts. While the core stealer is designed for short-burst execution and self-deletion, it often delivers persistent follow-on modules—ProManager, WinUpdate, SoftManager, and LockAppHost—which extend operational longevity through reverse proxies, clipboard manipulation, and privileged cryptocurrency mining.
Key Details
Threat Name
REVSTEALER
Affects
—
Adversary
REVSTEALER Other Adversaries and Aliases: REF2859
MITRE Techniques
Malware/Tools
REVSTEALER, ProManager, WinUpdate, SoftManager, LockAppHost, XMRig, Lumma Stealer, AuraStealer, LATRODECTUS, VoidStealer
