Security researchers from Elastic Security Labs are tracking an emerging Windows infostealer named REVSTEALER under activity cluster REF2859.
REVSTEALER is not only a simple password stealer. It is built like a wider theft platform that can profile the victim system, avoid sandboxes, steal browser and wallet data, use blockchain-based fallback infrastructure and receive additional modules from its command-and-control server.
Elastic reported that REVSTEALER has gained momentum in recent months and that a YARA Retrohunt returned around 4,700 matching samples across VirusTotal over the past year. The malware has been observed with gaming-related lures, but sample names and metadata also impersonate recognizable software such as Slack, qBittorrent, SteelSeries GG and Blender. [1]
Key Highlights
- Malware family: REVSTEALER
- Activity tracking: REF2859
- Malware type: Windows information stealer
- Primary targets: Browsers, cookies, passwords, wallets, gaming accounts, messaging apps, VPN data and local files
- Distribution theme: Free game cheats and mod menus
- Observed lure platforms: YouTube videos and hijacked YouTube channels
- Observed distribution domains:
elitecheatsx[.]liveandresight-cheats[.]net - Scale indicator: Around 4,700 matching samples found through Elastic’s VirusTotal Retrohunt
- Anti-analysis: CIS locale exclusions, sandbox scoring, API hashing, string encryption and indirect syscalls
- Browser theft: Includes a debugger-based method to access Chrome App-Bound Encryption material
- Wallet targeting: Tracks browser wallet extensions and standalone wallet applications
- Gaming targeting: Steam, Roblox, Minecraft, EA Desktop, Battle.net and other platforms
- C2 resilience: Uses Polygon smart contracts as fallback dead drops
- Follow-on modules: ProManager, WinUpdate, SoftManager and LockAppHost
- Detection support: Elastic published detection, prevention and YARA rules
- Severity: High
Initial Access Through Game-Cheat Lures
The observed campaign uses social engineering instead of a traditional enterprise phishing attachment.
Victims are attracted through videos advertising free cheats, mod menus or gaming tools. Elastic identified at least 17 YouTube channels promoting two related domains:
elitecheatsx[.]live
resight-cheats[.]netSome of these channels appeared to be hijacked accounts with existing subscriber bases. The attackers used short AI-generated videos to make the cheat tool look real and to push viewers toward the malicious download sites. [1]
The simplified infection path is:
Hijacked YouTube channel
↓
AI-generated cheat/mod video
↓
Malicious link in description
↓
Fake cheat download site
↓
REVSTEALER loader
↓
Credential and wallet theftThis is effective because the victim believes they are downloading a gaming advantage, not a malware payload.
More Than One Lure Theme
The gaming-cheat campaign is the clearest observed delivery theme, but it is not the only packaging style.
Elastic observed related submissions using names and metadata that impersonated common software, including:
- Slack
- qBittorrent
- SteelSeries GG
- Blender
- Other recognizable applications
This suggests that REVSTEALER can be repackaged for different victim groups.
The important point is:
REVSTEALER is not limited to gamers. The same stealer can be wrapped inside different lures depending on the target audience.
For enterprises, this means detection should not depend only on game-cheat keywords. Security teams should also monitor fake software downloads, cracked tools, unofficial installers and suspicious binaries using trusted brand names.
Development Style and Protection
REVSTEALER shows signs of active and organized development.
Elastic reports that many samples are packed with VMProtect, while the malware itself includes multiple features designed to slow down analysis. [1]
Observed protection and development features include:
- Self-deletion
- String encryption
- API hashing
- Indirect syscalls
- Custom exception handling
- VMProtect packing
- Control-flow obfuscation
- Anti-debugging behavior
- Sandbox scoring
- Payload watermarking
These features make the malware harder to inspect statically. A researcher may not immediately see readable strings, API names or configuration values inside the binary.
This does not make the malware impossible to analyze, but it increases the time and skill needed to unpack and understand it.
CIS Exclusion Checks
Before REVSTEALER fully qualifies a victim machine, it checks the system language and keyboard layout.
Elastic reported that REVSTEALER uses a custom FNV-1a hash lookup to compare the system’s default language, UI language and keyboard layout against values representing Commonwealth of Independent States locales. If one of these checks matches, the malware terminates. [1]
In simple terms:
Check system language
↓
Check UI language
↓
Check keyboard layout
↓
If CIS-region match appears
↓
Exit malwareThis type of exclusion is often used by financially motivated malware operators to avoid infecting certain regions and reduce local law-enforcement pressure.
Sandbox Scoring System
REVSTEALER includes a weighted sandbox scoring system.
Instead of relying on only one check, it calculates a score using multiple environment signals. If the score reaches 7 or higher, the malware treats the machine as a sandbox and stops execution. [1]
Elastic listed ten checks:
- Process blocklist
- CPU core count
- RAM threshold
- GPU / PCI vendor check
- Username / computer-name blocklist
- System uptime
- Sleep / timing check
- Media Foundation check
- CPUID check
- Virtualization check
This is more flexible than a simple “if VM then exit” check.
A real user system usually has normal RAM, realistic uptime, common processes, real GPU data and expected user activity. A sandbox may have low RAM, few CPU cores, suspicious tools, short uptime or virtualized hardware.
The malware scores these signals and then decides whether to continue.
Why the Sandbox Scoring Matters
The sandbox scoring system shows that REVSTEALER is built to protect itself before stealing data.
A simple infostealer may immediately collect files and credentials. REVSTEALER first asks:
Is this a real victim?
Is this a malware-analysis VM?
Are analysis tools running?
Is the environment too small or too artificial?
Should I exit before exposing my behavior?This makes automated analysis harder because the malware may refuse to run fully unless the environment looks realistic.
For defenders, the lesson is clear:
REVSTEALER detection should not depend only on the final theft stage. Earlier anti-analysis checks, unusual process behavior and suspicious environment profiling are also valuable detection points.
Credential Harvesting Scope
REVSTEALER has a broad credential-harvesting scope.
Elastic reported that it targets:
- Browser credentials
- Browser cookies
- Cryptocurrency wallets
- Browser wallet extensions
- Messaging applications
- Gaming platforms
- VPN data
- FTP clients
- OBS Studio
- Windows Sticky Notes
- Two-factor authentication applications
- Password managers
- Selected documents and configuration files
Elastic also reported that REVSTEALER targets 225 Chromium extension identifiers related to cryptocurrency wallets and password managers, along with 51 standalone wallet applications. [1]
This makes the malware dangerous for both personal and enterprise environments.
A single infected device may expose:
- Personal accounts
- Gaming accounts
- Wallet keys
- Browser sessions
- Corporate SSO sessions
- VPN profiles
- Cloud tokens
- Developer credentials
- Sensitive documents
Chrome App-Bound Encryption Bypass Behavior
Chrome introduced App-Bound Encryption to make cookie theft harder on Windows.
Google explained that App-Bound Encryption ties encrypted browser secrets to the application identity, so another app running as the same user should not simply decrypt Chrome data directly. Google also noted that malware would need more suspicious behavior, such as gaining elevated access or injecting into Chrome, to bypass the protection. [3]
REVSTEALER includes a debugger-based method to access Chrome App-Bound Encryption material.
Elastic reported that REVSTEALER launches a browser process under debugger control, locates code related to App-Bound decryption and places a hardware breakpoint near the target logic. When the breakpoint triggers, the malware reads the decrypted key from browser memory. [1]
In simple words:
Chrome protects cookie secrets
↓
REVSTEALER starts Chrome under debugger control
↓
It waits for Chrome to decrypt the key
↓
It reads the key directly from memory
↓
It uses the key to steal protected browser dataThis shows how modern stealers are adapting to browser security improvements.
Why Browser Cookies Are Valuable
Passwords are not the only target.
Session cookies can be even more useful because they may allow access to an account that is already logged in.
If an attacker steals valid browser session data, they may be able to access services without immediately needing the victim’s password. This is why cookie theft creates risk for:
- Cloud dashboards
- Developer platforms
- Crypto exchanges
- SaaS portals
- Admin consoles
- Social media accounts
- Gaming accounts
A password reset alone may not be enough if active sessions remain valid. After a confirmed infostealer infection, defenders should invalidate sessions, revoke tokens and rotate credentials from a clean system.
Victim Profiling Before Theft
Before launching stealing components, REVSTEALER profiles the victim machine.
Elastic listed the following profiling categories:
| Collected Data | Why It Matters |
|---|---|
| System and OS information | Helps identify the machine and understand the environment |
| Timestamp and locale | Helps map region and infection timing |
| CPU, RAM and GPU | Helps detect real machines versus sandboxes |
| Hostname and username | Helps label the victim |
| Timezone and keyboard layout | Helps infer region and target context |
| Screen resolution | Helps identify realistic user systems |
| Environment variables | May expose secrets, tokens or configuration values |
| Process list | Shows running apps and security tools |
| Installed applications | Reveals useful software and security products |
| Clipboard data | May contain passwords, wallet addresses or tokens |
| Screenshot | Gives the attacker visual context of the victim’s desktop |
Elastic specifically noted that REVSTEALER dumps the full environment block using GetEnvironmentStringsW, collects running processes, checks installed applications through the Windows uninstall registry path, captures clipboard data and takes a screenshot. [1]
This makes victim profiling part of the attack, not just a side feature.
Gaming Platform Targeting
REVSTEALER deliberately targets gaming platforms because gaming accounts can have resale value, stored payment value, rare items or marketplace assets.
Elastic reported targets including:
- Blizzard Battle.net
- Battlestate Games
- Electronic Arts / EA Desktop
- Roblox
- Steam
- Minecraft-related launchers and clients
For Roblox, REVSTEALER uses CryptUnprotectData to decrypt the user’s session cookie, enabling account takeover without the user’s password. [1]
This is important because the malware treats gaming accounts as monetizable assets, not just casual data.
Cryptocurrency Wallet Targeting
REVSTEALER has a multi-layer wallet theft design.
Elastic observed that the wallet harvester does not simply copy every random file. It uses a discovery layer and then a collector layer that applies wallet-specific filters.
This means the malware attempts to identify valuable wallet-related locations and extract relevant data more selectively.
Wallet targeting includes:
- Browser wallet extensions
- Standalone wallet applications
- Wallet configuration files
- Wallet session data
- Recovery-related material when available
For Web3 users, developers and crypto traders, this is high risk. One infected endpoint can expose wallet credentials, wallet browser extensions, seed-related material, cloud tokens and source-control access.
Payload Watermarking
Elastic reported that REVSTEALER uses a 16-byte watermark at the end of raw payloads.
When the raw unpacked payload is executed, it checks the watermark and displays a verification prompt asking for a random six-character token. Packed builds do not trigger the check in the same way because the watermark is no longer located at the end of the file. [1][2]
This serves two purposes:
- It discourages careless distribution of unpacked payloads.
- It makes automated sandbox execution more difficult.
This is a clever operator-control feature. It suggests the developer wants to protect raw builds from being freely reused or analyzed.
Polygon Dead Drops as Fallback C2
Each REVSTEALER build contains a primary C2 address and a Polygon smart-contract address.
If the primary C2 server becomes unreachable, the malware can query up to five public Polygon JSON-RPC endpoints, read data from the smart contract and decrypt a fallback C2 address using an embedded AES key. [1]
The fallback flow is:
REVSTEALER tries primary C2
↓
Primary C2 fails
↓
REVSTEALER queries Polygon RPC endpoints
↓
Smart contract returns encrypted fallback data
↓
Malware decrypts fallback C2
↓
REVSTEALER continues communicationThis is important because it makes the infrastructure more resilient.
A normal C2 domain can be blocked or taken down. A blockchain transaction or smart-contract value is harder to erase. Defenders can still block derived infrastructure and monitor RPC activity, but the resolver itself is more difficult to remove.
Example REVSTEALER Fallback Configurations
Elastic provided examples from different themed samples.
SteelSeriesGG.exe
C2: polygon.iwmukj[.]xyz:443
Polygon contract: 0x7e4126ADFE6679B3613F629CD49162Fb08fc53Bd
Function selector: 0xdbefdad6slack.exe
C2: polygon.mnyhgxda[.]xyz:443
Polygon contract: 0x0EC6a6D31b36271eBD06450EA98c84eBa8a191d5
Function selector: 0xd21368b4qBittorrent.exe
C2: static4.livelab[.]one:443
Polygon contract: 0x49cE5712164755ed212209bc71539bBc6fCFF541
Function selector: 0x071258c6These examples show how the same malware family can support different themes while keeping a backup C2 mechanism through Polygon. [1]
Polygon Contract Artifacts for Hunting
The following Polygon contract addresses are useful for threat hunting and blockchain-based infrastructure tracking. They should not be added to the normal IoC panel because the current indicator form does not support wallet or smart-contract artifact types.
0x7e4126ADFE6679B3613F629CD49162Fb08fc53Bd
0x0EC6a6D31b36271eBD06450EA98c84eBa8a191d5
0x49cE5712164755ed212209bc71539bBc6fCFF541
0x98FF8e7cdC13AE46b83B7590B986F25f1560DF03
0x0cF1Ec8B9551103de729c3b02D77221Da9d81Acc
0x0E04c59f31E382D2B8A1637f4B9A5f04165EC48d
0xC4eC9B7be1c2A0B39Eca678673DcB9164CA5df53Four Linked Follow-On Modules
REVSTEALER can receive additional executable content through C2 tasking.
Elastic recovered four linked modules:
| Module | Main Capability |
|---|---|
| ProManager | Wallet-file theft, browser-extension theft, phishing overlays, password-aware input capture and payload delivery |
| WinUpdate | Cryptocurrency-address replacement and mnemonic-shaped clipboard theft |
| SoftManager | Reverse SOCKS5 proxy and encrypted WebSocket backconnect access |
| LockAppHost | XMRig deployment, competitor suspension and persistence |
Elastic noted that these modules share design patterns such as obfuscated configuration, VMProtect-style protection and Polygon smart contracts used as dead drops for replaceable settings. [1]
The Hacker News also summarized that these linked modules can remain on an infected machine after the core stealer deletes itself, with capabilities such as wallet theft, proxying and cryptocurrency mining.
Why the Follow-On Modules Change the Risk
A normal stealer may run once, collect data and delete itself.
REVSTEALER’s linked modules make the risk deeper.
After the first theft phase, the attacker may still have:
- Wallet overlay capability
- Clipboard monitoring
- Crypto-address replacement
- Reverse proxy access
- Backconnect capability
- Miner deployment
- Persistence through separate components
This means incident responders should not assume the attack is over just because the main stealer deleted itself.
The better response is:
Find the stealer
↓
Check whether modules were dropped
↓
Search persistence locations
↓
Review proxy/miner behavior
↓
Reset credentials and sessions
↓
Rebuild if scope is unclearWhat This Article Adds
Most REVSTEALER reporting focuses on what the malware steals.
The defender-focused angle here is different:
REVSTEALER should be treated as an account-value harvesting platform, not only as a password stealer.
The malware does four important things before and after stealing:
- It attracts high-value users through game cheats, fake tools and recognizable software themes.
- It validates the environment using CIS checks, sandbox scoring and anti-analysis logic.
- It collects account-value signals through browser data, wallet files, gaming sessions, clipboard data and installed applications.
- It maintains operational resilience through Polygon fallback C2 and linked follow-on modules.
The core idea is:
Lure quality
+
Victim validation
+
Credential harvesting
+
Blockchain fallback
+
Post-steal modules
=
More durable account-theft operationThat is the main analytical contribution of this article.
REVSTEALER is not just stealing files. It is identifying which victims are valuable, avoiding weak analysis environments, collecting multiple account types and giving operators optional follow-on tools for deeper monetization.
Attack Chain
The observed attack chain can be summarized as:
Hijacked YouTube Channel → AI-Generated Cheat Video → Malicious Cheat Website → REVSTEALER Loader → Anti-Analysis Checks → Victim Profiling → Browser, Wallet and Gaming Theft → C2 Exfiltration → Self-Deletion → Optional Follow-On Modules
A second view focused on infrastructure resilience is:
Primary C2 → Failure or Blocking → Polygon JSON-RPC Query → Smart Contract Response → AES-Decrypted Fallback C2 → Continued Operator Access
A third view focused on enterprise risk is:
User Downloads Fake Tool → Browser Cookies and Passwords Stolen → Session Tokens Exposed → Cloud, VPN, Wallet, Gaming or Developer Accounts at Risk
Detection and Hunting Opportunities
Security teams should monitor for:
- Users downloading free cheats, mod menus or cracked tools
- Links to
elitecheatsx[.]liveorresight-cheats[.]net - Executables pretending to be popular software such as Slack, qBittorrent, SteelSeries GG or Blender
- Packed executables using VMProtect
- Executables that delete themselves after execution
- Binaries that display unusual verification or PIN prompts
- Processes performing CIS language or keyboard-layout checks
- Multiple sandbox checks executed before main malware behavior
- Process enumeration followed by self-termination
- Low-level API resolution and API hashing behavior
- Indirect syscall usage from unsigned or low-reputation binaries
- Suspicious use of hardware breakpoints near browser decryption logic
- A non-browser process launching Chrome or another browser under debugger control
- Chrome App-Bound Encryption access attempts
- Access to browser cookie and credential databases
- Access to Chromium extension folders
- Access to cryptocurrency wallet directories
- Access to standalone wallet application files
- Access to Telegram Desktop data
- Access to VPN configuration or key material
- Access to FTP client configuration files
- Access to OBS Studio data
- Access to Windows Sticky Notes
- Access to password-manager or 2FA application data
- Clipboard access immediately before or after credential theft
- Screenshot capture by an unknown executable
- Roblox cookie decryption using
CryptUnprotectData - Reads from Steam, EA Desktop, Battle.net or Minecraft launcher paths
- Connections to suspicious
.click,.lol,.xyzor similar domains - Queries to public Polygon JSON-RPC endpoints from unknown executables
- Smart-contract reads followed by decryption and a new C2 connection
- Executables named ProManager, WinUpdate, SoftManager or LockAppHost
- Reverse SOCKS5 proxy behavior from a user workstation
- Encrypted WebSocket backconnect traffic
- Cryptocurrency-address replacement in clipboard data
- Mnemonic-shaped text collection
- XMRig miner deployment or miner-like CPU behavior
- Microsoft Defender exclusion changes
- Windows Update service or scheduled-task tampering
A strong REVSTEALER hunting sequence is:
Fake Cheat Download → Packed Windows Executable → Anti-Analysis Checks → Browser Debugging or Credential Access → Polygon RPC Query → C2 Communication
A strong enterprise identity-risk sequence is:
Unknown Executable → Browser Cookie Access → Session Token Exposure → New Cloud Login or Account Access From Unusual Location
Host-Based Hunting Artifacts
Keep these in the article body, not in the IoC panel if the portal does not support file-path indicators.
%LOCALAPPDATA%\Battle.net\Battle.net.config
%APPDATA%\Battlestate Games\BsgLauncher\settings
%LOCALAPPDATA%\Electronic Arts\EA Desktop\*.ini
%LOCALAPPDATA%\Roblox\LocalStorage\RobloxCookies.dat
%LOCALAPPDATA%\Steam\local.vdf
%LOCALAPPDATA%\Steam\loginusers.vdf
%USERPROFILE%\intentlauncher\launcherconfig
%USERPROFILE%\.lunarclient\settings\game\accounts.json
%APPDATA%\.minecraft\TlauncherProfiles.json
%APPDATA%\.feather\accounts.json
%APPDATA%\.minecraft\meteor-client\accounts.nbt
%APPDATA%\Badlion Client\accounts.json
%APPDATA%\.minecraft\launcher_accounts.json
%APPDATA%\.minecraft\launcher_profiles_microsoft_store.json
SOFTWARE\Microsoft\Windows\CurrentVersion\UninstallRecommended Mitigations
- Block access to known malicious REVSTEALER domains.
- Block downloads from unofficial cheat, mod-menu and cracked-software sites.
- Educate users that free game cheats and cracked tools are common malware delivery methods.
- Monitor hijacked or suspicious YouTube channels promoting software downloads.
- Prevent execution of unsigned or low-reputation binaries from Downloads and Temp folders.
- Use application control to restrict unknown executables.
- Detect packed binaries using VMProtect or similar protectors.
- Monitor binaries that self-delete after execution.
- Alert on suspicious browser debugging activity.
- Alert when non-browser processes access Chrome credential or cookie stores.
- Monitor Chrome App-Bound Encryption bypass indicators.
- Investigate failed Chrome App-Bound verification events where available.
- Monitor access to wallet browser-extension folders.
- Monitor access to standalone wallet application directories.
- Protect seed phrases and wallet keys using offline or hardware-backed storage.
- Do not store wallet recovery phrases in clipboard-accessible notes, screenshots or local documents.
- Monitor clipboard access by unknown processes.
- Invalidate active browser sessions after suspected infostealer infection.
- Rotate passwords from a clean device.
- Revoke exposed cloud, VPN, GitHub, email and SaaS tokens.
- Monitor Polygon JSON-RPC access from endpoints that do not require blockchain access.
- Block or alert on known REVSTEALER C2 domains.
- Hunt for ProManager, WinUpdate, SoftManager and LockAppHost indicators.
- Check for proxy, backconnect and miner behavior after the main stealer is removed.
- Review Windows Defender exclusions and Windows Update settings after suspected LockAppHost activity.
- Re-enable disabled security and update services if tampering is found.
- Collect memory and endpoint telemetry before rebooting if active malware is suspected.
- Rebuild the endpoint when the full scope of credential theft and module deployment cannot be confirmed.
Threat Assessment
This activity should be assessed as High severity.
REVSTEALER can expose browser credentials, session cookies, cryptocurrency wallets, gaming accounts, VPN data, messaging data, local files and system information.
The risk is higher because the malware combines credential harvesting with:
- Anti-analysis logic
- VMProtect packing
- App-Bound Encryption bypass behavior
- Victim profiling
- Polygon fallback C2
- Self-deletion
- Follow-on modules
- Wallet overlays
- Proxy access
- Clipboard manipulation
- Mining capability
A Critical rating may be appropriate internally for organizations where infected endpoints have access to production wallets, privileged cloud accounts, CI/CD secrets, source-control credentials or financial systems.
For general reporting, High is the best public severity because the available reporting does not prove destructive behavior, ransomware deployment, zero-day exploitation or a single large confirmed enterprise breach.
Research Boundaries
Do not overclaim the following:
- Do not claim every REVSTEALER sample uses the same lure.
- Do not claim every infected host receives all four follow-on modules.
- Do not claim Polygon infrastructure makes the malware untakable.
- Do not claim a specific nation-state actor unless new evidence appears.
- Do not claim VMProtect means a file is always malicious.
- Do not claim App-Bound Encryption is broken for all use cases.
- Do not claim gaming users are the only targets.
The safe assessment is:
REVSTEALER is an emerging, actively developed infostealer ecosystem that combines broad credential harvesting, anti-analysis, resilient fallback infrastructure and post-steal monetization modules.
Conclusion
REVSTEALER shows how modern infostealers are becoming more organized and harder to treat as simple one-time credential grabbers.
The malware uses social engineering to attract victims, checks whether the machine looks real, collects system and account-value signals, steals browser and wallet data, and can rely on Polygon smart contracts when primary infrastructure fails.
Its targeting of gaming platforms is also important. Steam, Roblox, Minecraft and other gaming accounts are not just personal entertainment accounts anymore. They can hold resale value, payment data, rare assets and reusable identity signals.
For enterprises, the biggest concern is session and token exposure. If an employee runs REVSTEALER on a personal or work system, the attacker may obtain browser cookies, cloud sessions, VPN material, wallet data and developer credentials.
The strongest defense is not only hash blocking. Security teams should connect the full behavior:
- Where did the download come from?
- Was the file pretending to be a cheat or popular app?
- Did it perform anti-analysis checks?
- Did it touch browser secrets or wallet folders?
- Did it query Polygon RPC infrastructure?
- Did it connect to a suspicious C2?
- Did follow-on modules remain after the stealer deleted itself?
REVSTEALER should be treated as a serious credential, wallet and account-takeover threat.