Threat Advisory

REVSTEALER Infostealer Targets Browsers and Gaming Accounts with Credential Theft

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Threat Command REVSTEALER ramps up: analysis of up-and-coming infostealer. Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months with higher distribution volume and has emerged as a formidable threat featuring a comprehensive credential harvester. REVSTEALER targets browsers wallets and gaming accounts. The malware incorporates features such as self-deletion indirect syscalls API hashing string encryption mechanisms to avoid user-mode hooks and custom exception handling.

It uses a multi-layer architecture for its cryptocurrency wallet harvester which applies wallet-specific extension filters to extract only relevant files. Before qualifying the victim machine REVSTEALER checks the machine's default/system languages and keyboard layout using a custom hash lookup. REVSTEALER is a threat with widespread use of VMProtect packer in most samples; unpacked samples display a verification prompt similar to LummaStealer and AuraStealer.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Threat Command REVSTEALER ramps up: analysis of up-and-coming infostealer. Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months with higher distribution volume and has emerged as a formidable threat featuring a comprehensive credential harvester. REVSTEALER targets browsers wallets and gaming accounts. The malware incorporates features such as self-deletion indirect syscalls API hashing string encryption mechanisms to avoid user-mode hooks and custom exception handling.

It uses a multi-layer architecture for its cryptocurrency wallet harvester which applies wallet-specific extension filters to extract only relevant files. Before qualifying the victim machine REVSTEALER checks the machine's default/system languages and keyboard layout using a custom hash lookup. REVSTEALER is a threat with widespread use of VMProtect packer in most samples; unpacked samples display a verification prompt similar to LummaStealer and AuraStealer.[emaillocker id="1283"]

The malware has been observed targeting gaming platforms for additional monetization and has a Polygon blockchain-based dead drop for resilience. It features a comprehensive credential harvester an embedded sandbox scoring system and tasking delivers four modules not previously documented publicly. REVSTEALER is a threat that defenders must be aware of as it continues to evolve and gain momentum.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1204.002 User Execution Malicious File
Defence Evasion T1027.002 Obfuscated Files or Information Software Packing
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1567.002 Exfiltration Over Web Service Exfiltration to Cloud Storage

MBC MAPPING:

Objective Behavior ID Behavior
Discovery E1083 File and Directory Discovery
Defense Evasion B0029 Polymorphic Code
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Anti-Static Analysis E1027 Obfuscated Files or Information

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu