REVSTEALER ramps up: analysis of up-and-coming infostealer
An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-...
AI Analysis
Technical Summary
REVSTEALER is a sophisticated credential-stealing malware family tracked under REF2859, notable for its comprehensive targeting of various credential stores including browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates advanced anti-analysis features such as a weighted sandbox scoring system to evade detection and uses Polygon blockchain-based dead drops to maintain resilient infrastructure. The malware is primarily distributed via social engineering campaigns targeting gamers through compromised YouTube channels promoting fake game cheats, with some samples impersonating legitimate applications like Slack and qBittorrent. It delivers four additional modules that extend its capabilities to wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. The majority of samples are protected with VMProtect packing and include an App-Bound Encryption bypass technique involving debugger evasion. No known exploits in the wild have been reported, and no patches or remediation guidance are applicable as this is malware rather than a software vulnerability.
Potential Impact
REVSTEALER compromises user credentials across multiple platforms and applications, potentially leading to unauthorized access to sensitive accounts including cryptocurrency wallets and gaming platforms. Its modular design allows additional malicious activities such as clipboard data theft, establishing reverse proxies for network pivoting, and deploying cryptocurrency miners, which can degrade system performance and increase operational costs. The use of advanced evasion techniques complicates detection and analysis, increasing the risk of prolonged undetected infections.
Mitigation Recommendations
As this is malware rather than a software vulnerability, no patches are available. Mitigation should focus on user education to avoid social engineering traps, especially fake game cheats advertised on compromised YouTube channels. Employ robust endpoint protection solutions capable of detecting VMProtect-packed malware and sandbox evasion techniques. Monitor for suspicious application impersonation (e.g., Slack, qBittorrent) and restrict execution of unauthorized software. Regularly update security tools and threat intelligence feeds to detect emerging variants. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.
Indicators of Compromise
- hash: 4c897108e8e793d6904110928c996815c302d6975c9bc61162149e855a963d50
- hash: face4acb042c323fca0ead3463d0e896
- hash: b3f6efdbac7547ee988417c636a9eea999e8eebb
- domain: resight-cheats.net
- hash: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5
- hash: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2
- hash: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa
- domain: monitor5.roast-core85.click
- hash: 5f8430227835881d5451bb0c083c2401
- hash: 52c921a7cea0d0471cfe61291a6c69345c2cde64
- domain: metric.gardenpark.click
- domain: config.hubdisplay.lol
- hash: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb
- hash: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4
- domain: health.journal-metric.lol
- hash: 0187bf1ef6341b0eb52e2dc0a1fef693
- hash: 1cfdd65fa43a819bfce1f7f322565098
- hash: 22cc17db39122a759fb63c521f1096d1
- hash: 73650b24e045a4636ffba752fdb5b743
- hash: 9b42816d0a8f4659e51514f275a7e50c
- hash: de2f77d1b0e9d6eb24799fa3c7b4047e
- hash: 5aca97cc7a6f253ffc9e3738353c236363835529
- hash: 6da138326647ee1a7161311bf3b7a903ad27b5c1
- hash: 8a3d4f66cd8522f96fecb02870c1da59fd4968ce
- hash: cbb414de10499565a6eef28c24f75bb5128acadc
- hash: d90602ed7d09621b1c7a25f8dbab228795b23bc0
- hash: fdb4c185004dbe8f5de441faef5c09b25cc136f8
- hash: 1617552169df805405b1bb70f742d6eac5af342f31c6e39ff6b9613bd2392354
- hash: 5c30efd5b9ff75023c3813705f5c47feccc496f439b24b3e572db4c3b08dffe3
- hash: 83f5b4ca629681abab2b9680472a304572a8c91b4a8ccc1189fbf58c6186db09
- hash: 8b33e0f32c42a317e3d9cd67d5a6dc68e91a6cf9dd44742162858e7d83cf2073
- hash: bd97d5cab2d09b001d1b9e08890bce1a2b2cf8542a4b31c86b2def59328cafb2
- hash: f07666ac22dfa1a361b8a8576baf69eadaf15431db9f3c34e93334d8d2f8d691
- domain: elitecheatsx.live
- domain: polygon.iwmukj.xyz
- domain: polygon.mnyhgxda.xyz
- domain: static4.livelab.one
REVSTEALER ramps up: analysis of up-and-coming infostealer
Description
An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
REVSTEALER is a sophisticated credential-stealing malware family tracked under REF2859, notable for its comprehensive targeting of various credential stores including browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates advanced anti-analysis features such as a weighted sandbox scoring system to evade detection and uses Polygon blockchain-based dead drops to maintain resilient infrastructure. The malware is primarily distributed via social engineering campaigns targeting gamers through compromised YouTube channels promoting fake game cheats, with some samples impersonating legitimate applications like Slack and qBittorrent. It delivers four additional modules that extend its capabilities to wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. The majority of samples are protected with VMProtect packing and include an App-Bound Encryption bypass technique involving debugger evasion. No known exploits in the wild have been reported, and no patches or remediation guidance are applicable as this is malware rather than a software vulnerability.
Potential Impact
REVSTEALER compromises user credentials across multiple platforms and applications, potentially leading to unauthorized access to sensitive accounts including cryptocurrency wallets and gaming platforms. Its modular design allows additional malicious activities such as clipboard data theft, establishing reverse proxies for network pivoting, and deploying cryptocurrency miners, which can degrade system performance and increase operational costs. The use of advanced evasion techniques complicates detection and analysis, increasing the risk of prolonged undetected infections.
Defensive Guidance
As this is malware rather than a software vulnerability, no patches are available. Mitigation should focus on user education to avoid social engineering traps, especially fake game cheats advertised on compromised YouTube channels. Employ robust endpoint protection solutions capable of detecting VMProtect-packed malware and sandbox evasion techniques. Monitor for suspicious application impersonation (e.g., Slack, qBittorrent) and restrict execution of unauthorized software. Regularly update security tools and threat intelligence feeds to detect emerging variants. There is no vendor advisory indicating that no action is required or that the threat is already mitigated.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.elastic.co/security-labs/threat-command/revstealer-credential-harvesting-infostealer"]
- Adversary
- null
- Pulse Id
- 6a9d57d410d16313f7424f67
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash4c897108e8e793d6904110928c996815c302d6975c9bc61162149e855a963d50 | — | |
hashface4acb042c323fca0ead3463d0e896 | — | |
hashb3f6efdbac7547ee988417c636a9eea999e8eebb | — | |
hashc66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 | — | |
hash14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 | — | |
hash13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa | — | |
hash5f8430227835881d5451bb0c083c2401 | — | |
hash52c921a7cea0d0471cfe61291a6c69345c2cde64 | — | |
hash7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb | — | |
hashadc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 | — | |
hash0187bf1ef6341b0eb52e2dc0a1fef693 | — | |
hash1cfdd65fa43a819bfce1f7f322565098 | — | |
hash22cc17db39122a759fb63c521f1096d1 | — | |
hash73650b24e045a4636ffba752fdb5b743 | — | |
hash9b42816d0a8f4659e51514f275a7e50c | — | |
hashde2f77d1b0e9d6eb24799fa3c7b4047e | — | |
hash5aca97cc7a6f253ffc9e3738353c236363835529 | — | |
hash6da138326647ee1a7161311bf3b7a903ad27b5c1 | — | |
hash8a3d4f66cd8522f96fecb02870c1da59fd4968ce | — | |
hashcbb414de10499565a6eef28c24f75bb5128acadc | — | |
hashd90602ed7d09621b1c7a25f8dbab228795b23bc0 | — | |
hashfdb4c185004dbe8f5de441faef5c09b25cc136f8 | — | |
hash1617552169df805405b1bb70f742d6eac5af342f31c6e39ff6b9613bd2392354 | — | |
hash5c30efd5b9ff75023c3813705f5c47feccc496f439b24b3e572db4c3b08dffe3 | — | |
hash83f5b4ca629681abab2b9680472a304572a8c91b4a8ccc1189fbf58c6186db09 | — | |
hash8b33e0f32c42a317e3d9cd67d5a6dc68e91a6cf9dd44742162858e7d83cf2073 | — | |
hashbd97d5cab2d09b001d1b9e08890bce1a2b2cf8542a4b31c86b2def59328cafb2 | — | |
hashf07666ac22dfa1a361b8a8576baf69eadaf15431db9f3c34e93334d8d2f8d691 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainresight-cheats.net | — | |
domainmonitor5.roast-core85.click | — | |
domainmetric.gardenpark.click | — | |
domainconfig.hubdisplay.lol | — | |
domainhealth.journal-metric.lol | — | |
domainelitecheatsx.live | — | |
domainpolygon.iwmukj.xyz | — | |
domainpolygon.mnyhgxda.xyz | — | |
domainstatic4.livelab.one | — |
Threat ID: 6a9e897bacd9273b495766cb
Added to database: 09/07/2026, 09:52:59 UTC
Last enriched: 09/07/2026, 10:08:12 UTC
Last updated: 09/07/2026, 12:54:30 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.