Threat Command REVSTEALER ramps up: analysis of up-and-coming infostealer. Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months with higher distribution volume and has emerged as a formidable threat featuring a comprehensive credential harvester. REVSTEALER targets browsers wallets and gaming accounts. The malware incorporates features such as self-deletion indirect syscalls API hashing string encryption mechanisms to avoid user-mode hooks and custom exception handling.
It uses a multi-layer architecture for its cryptocurrency wallet harvester which applies wallet-specific extension filters to extract only relevant files. Before qualifying the victim machine REVSTEALER checks the machine's default/system languages and keyboard layout using a custom hash lookup. REVSTEALER is a threat with widespread use of VMProtect packer in most samples; unpacked samples display a verification prompt similar to LummaStealer and AuraStealer.[/subscribe_to_unlock_form]
Threat Command REVSTEALER ramps up: analysis of up-and-coming infostealer. Elastic Security Labs is tracking an emerging infostealer, REVSTEALER, under REF2859. This family has gained momentum in recent months with higher distribution volume and has emerged as a formidable threat featuring a comprehensive credential harvester. REVSTEALER targets browsers wallets and gaming accounts. The malware incorporates features such as self-deletion indirect syscalls API hashing string encryption mechanisms to avoid user-mode hooks and custom exception handling.
It uses a multi-layer architecture for its cryptocurrency wallet harvester which applies wallet-specific extension filters to extract only relevant files. Before qualifying the victim machine REVSTEALER checks the machine's default/system languages and keyboard layout using a custom hash lookup. REVSTEALER is a threat with widespread use of VMProtect packer in most samples; unpacked samples display a verification prompt similar to LummaStealer and AuraStealer.[emaillocker id="1283"]
The malware has been observed targeting gaming platforms for additional monetization and has a Polygon blockchain-based dead drop for resilience. It features a comprehensive credential harvester an embedded sandbox scoring system and tasking delivers four modules not previously documented publicly. REVSTEALER is a threat that defenders must be aware of as it continues to evolve and gain momentum.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1204.002 | User Execution | Malicious File |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1567.002 | Exfiltration Over Web Service | Exfiltration to Cloud Storage |
| Objective | Behavior ID | Behavior |
|---|---|---|
| Discovery | E1083 | File and Directory Discovery |
| Defense Evasion | B0029 | Polymorphic Code |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
The following reports contain further technical details:
[/emaillocker]