Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

REVSTEALER ramps up: analysis of up-and-coming infostealer

0
Medium
Published: 09/06/2026 (09/06/2026, 12:08:52 UTC)
Source: AlienVault OTX General

Description

An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 10:08:12 UTC

Technical Analysis

REVSTEALER is a sophisticated credential-stealing malware family tracked under REF2859, notable for its comprehensive targeting of various credential stores including browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates advanced anti-analysis features such as a weighted sandbox scoring system to evade detection and uses Polygon blockchain-based dead drops to maintain resilient infrastructure. The malware is primarily distributed via social engineering campaigns targeting gamers through compromised YouTube channels promoting fake game cheats, with some samples impersonating legitimate applications like Slack and qBittorrent. It delivers four additional modules that extend its capabilities to wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. The majority of samples are protected with VMProtect packing and include an App-Bound Encryption bypass technique involving debugger evasion. No known exploits in the wild have been reported, and no patches or remediation guidance are applicable as this is malware rather than a software vulnerability.

Potential Impact

REVSTEALER compromises user credentials across multiple platforms and applications, potentially leading to unauthorized access to sensitive accounts including cryptocurrency wallets and gaming platforms. Its modular design allows additional malicious activities such as clipboard data theft, establishing reverse proxies for network pivoting, and deploying cryptocurrency miners, which can degrade system performance and increase operational costs. The use of advanced evasion techniques complicates detection and analysis, increasing the risk of prolonged undetected infections.

Defensive Guidance

As this is malware rather than a software vulnerability, no patches are available. Mitigation should focus on user education to avoid social engineering traps, especially fake game cheats advertised on compromised YouTube channels. Employ robust endpoint protection solutions capable of detecting VMProtect-packed malware and sandbox evasion techniques. Monitor for suspicious application impersonation (e.g., Slack, qBittorrent) and restrict execution of unauthorized software. Regularly update security tools and threat intelligence feeds to detect emerging variants. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer"]
Adversary
null
Pulse Id
6a9d57d410d16313f7424f67
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash4c897108e8e793d6904110928c996815c302d6975c9bc61162149e855a963d50
hashface4acb042c323fca0ead3463d0e896
hashb3f6efdbac7547ee988417c636a9eea999e8eebb
hashc66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5
hash14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2
hash13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa
hash5f8430227835881d5451bb0c083c2401
hash52c921a7cea0d0471cfe61291a6c69345c2cde64
hash7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb
hashadc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4
hash0187bf1ef6341b0eb52e2dc0a1fef693
hash1cfdd65fa43a819bfce1f7f322565098
hash22cc17db39122a759fb63c521f1096d1
hash73650b24e045a4636ffba752fdb5b743
hash9b42816d0a8f4659e51514f275a7e50c
hashde2f77d1b0e9d6eb24799fa3c7b4047e
hash5aca97cc7a6f253ffc9e3738353c236363835529
hash6da138326647ee1a7161311bf3b7a903ad27b5c1
hash8a3d4f66cd8522f96fecb02870c1da59fd4968ce
hashcbb414de10499565a6eef28c24f75bb5128acadc
hashd90602ed7d09621b1c7a25f8dbab228795b23bc0
hashfdb4c185004dbe8f5de441faef5c09b25cc136f8
hash1617552169df805405b1bb70f742d6eac5af342f31c6e39ff6b9613bd2392354
hash5c30efd5b9ff75023c3813705f5c47feccc496f439b24b3e572db4c3b08dffe3
hash83f5b4ca629681abab2b9680472a304572a8c91b4a8ccc1189fbf58c6186db09
hash8b33e0f32c42a317e3d9cd67d5a6dc68e91a6cf9dd44742162858e7d83cf2073
hashbd97d5cab2d09b001d1b9e08890bce1a2b2cf8542a4b31c86b2def59328cafb2
hashf07666ac22dfa1a361b8a8576baf69eadaf15431db9f3c34e93334d8d2f8d691

Domain

ValueDescriptionCopy
domainresight-cheats.net
domainmonitor5.roast-core85.click
domainmetric.gardenpark.click
domainconfig.hubdisplay.lol
domainhealth.journal-metric.lol
domainelitecheatsx.live
domainpolygon.iwmukj.xyz
domainpolygon.mnyhgxda.xyz
domainstatic4.livelab.one

Threat ID: 6a9e897bacd9273b495766cb

Added to database: 09/07/2026, 09:52:59 UTC

Last enriched: 09/07/2026, 10:08:12 UTC

Last updated: 09/07/2026, 12:54:30 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses