EXECUTIVE SUMMARY:
RevStealer is a Windows-based information-stealing malware distributed through trojanized software, including a fake "Claude Opus 5 Free Desktop" application hosted on GitHub and game-cheat-themed websites. The campaign uses social engineering to convince users to download what appears to be legitimate software. Once executed, the malicious Electron application operates without displaying a visible interface, validates the victim environment, and covertly deploys the RevStealer payload.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
RevStealer is a Windows-based information-stealing malware distributed through trojanized software, including a fake "Claude Opus 5 Free Desktop" application hosted on GitHub and game-cheat-themed websites. The campaign uses social engineering to convince users to download what appears to be legitimate software. Once executed, the malicious Electron application operates without displaying a visible interface, validates the victim environment, and covertly deploys the RevStealer payload.[emaillocker id="1283"]
The malware employs multiple evasion and anti-analysis mechanisms to reduce its visibility and resist automated investigation. The loader performs memory, CPU, GPU, hostname, and username checks, while the native payload uses VM and sandbox detection, language-based exclusions, CAPTCHA validation, encrypted configuration, concealed API resolution, and indirect system calls designed to bypass common user-mode monitoring hooks. RevStealer establishes command-and-control communication through an encrypted endpoint and maintains a blockchain-based fallback mechanism using a Polygon smart contract, allowing its operators to change infrastructure without rebuilding the malware. The stealer collects extensive information, including browser databases and credentials, password-manager artifacts, cryptocurrency-wallet data, VPN and remote-access credentials, messaging and gaming application data, clipboard contents, screenshots, and selected user files. Stolen information is structured, encrypted, and transmitted incrementally rather than being accumulated in a large archive on disk.
RevStealer represents a highly evasive information-stealing designed to minimize its operational footprint and reduce the time available for detection and response. Its combination of trusted-platform abuse, a convincing software lure, environment-aware execution, anti-analysis mechanisms, encrypted data transmission, blockchain-based C2 failover, and self-deletion enables rapid credential, session, and cryptocurrency theft. The stolen VPN, remote-access, browser, and authentication data could also provide an entry point for follow-on intrusion activity, making RevStealer a significant threat to Windows users and organizations.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1195.002 | Supply Chain Compromise | Compromise Software Supply Chain |
| Stealth | T1027.002 | Obfuscated Files or Information | Software Packing |
| Stealth | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Stealth | T1070.004 | Indicator Removal | File Deletion |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1105 | Ingress Tool Transfer | - |
| Command and control | T1573.001 | Encrypted Channel | Symmetric Cryptography |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC PROFILE:
| Objective | Behavior ID | Behavior |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Anti-Behavioral Analysis | B0003 | Dynamic Analysis Evasion |
| Command & Control | B0030 | C2 Communication |
| Defense Evasion | F0004 | Disable or Evade Security Tools |
| Execution | E1204 | User Execution |
| Exfiltration | E1020 | Automated Exfiltration |
| Discovery | E1083 | File and Directory Discovery |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Cryptography Micro-objective | C0027 | Encrypt Data |
| Impact | B0022 | Remote Access |
REFERENCES:
The following reports contain further technical details:
https://engage.morphisec.com/hubfs/2026-PDFs/RevStealer_ThreatAnalysis_5.pdf?hsCtaTracking=447889b7-2421-4a80-b283-5980955d8331%7C0947984a-dda2-4c41-a487-93f935c935bf