Threat Advisory

RevStealer Malware Steals Web Credentials and Passwords via Fake AI Repository

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

RevStealer is a Windows-based information-stealing malware distributed through trojanized software, including a fake "Claude Opus 5 Free Desktop" application hosted on GitHub and game-cheat-themed websites. The campaign uses social engineering to convince users to download what appears to be legitimate software. Once executed, the malicious Electron application operates without displaying a visible interface, validates the victim environment, and covertly deploys the RevStealer payload.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

RevStealer is a Windows-based information-stealing malware distributed through trojanized software, including a fake "Claude Opus 5 Free Desktop" application hosted on GitHub and game-cheat-themed websites. The campaign uses social engineering to convince users to download what appears to be legitimate software. Once executed, the malicious Electron application operates without displaying a visible interface, validates the victim environment, and covertly deploys the RevStealer payload.[emaillocker id="1283"]

The malware employs multiple evasion and anti-analysis mechanisms to reduce its visibility and resist automated investigation. The loader performs memory, CPU, GPU, hostname, and username checks, while the native payload uses VM and sandbox detection, language-based exclusions, CAPTCHA validation, encrypted configuration, concealed API resolution, and indirect system calls designed to bypass common user-mode monitoring hooks. RevStealer establishes command-and-control communication through an encrypted endpoint and maintains a blockchain-based fallback mechanism using a Polygon smart contract, allowing its operators to change infrastructure without rebuilding the malware. The stealer collects extensive information, including browser databases and credentials, password-manager artifacts, cryptocurrency-wallet data, VPN and remote-access credentials, messaging and gaming application data, clipboard contents, screenshots, and selected user files. Stolen information is structured, encrypted, and transmitted incrementally rather than being accumulated in a large archive on disk.

RevStealer represents a highly evasive information-stealing designed to minimize its operational footprint and reduce the time available for detection and response. Its combination of trusted-platform abuse, a convincing software lure, environment-aware execution, anti-analysis mechanisms, encrypted data transmission, blockchain-based C2 failover, and self-deletion enables rapid credential, session, and cryptocurrency theft. The stolen VPN, remote-access, browser, and authentication data could also provide an entry point for follow-on intrusion activity, making RevStealer a significant threat to Windows users and organizations.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1195.002 Supply Chain Compromise Compromise Software Supply Chain
Stealth T1027.002 Obfuscated Files or Information Software Packing
Stealth T1036.005 Masquerading Match Legitimate Resource Name or Location
Stealth T1070.004 Indicator Removal File Deletion
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1105 Ingress Tool Transfer -
Command and control T1573.001 Encrypted Channel Symmetric Cryptography
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC PROFILE:

Objective Behavior ID Behavior
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Behavioral Analysis B0003 Dynamic Analysis Evasion
Command & Control B0030 C2 Communication
Defense Evasion F0004 Disable or Evade Security Tools
Execution E1204 User Execution
Exfiltration E1020 Automated Exfiltration
Discovery E1083 File and Directory Discovery
Persistence F0012 Registry Run Keys / Startup Folder
Cryptography Micro-objective C0027 Encrypt Data
Impact B0022 Remote Access

 

REFERENCES:

The following reports contain further technical details:
https://engage.morphisec.com/hubfs/2026-PDFs/RevStealer_ThreatAnalysis_5.pdf?hsCtaTracking=447889b7-2421-4a80-b283-5980955d8331%7C0947984a-dda2-4c41-a487-93f935c935bf

[/emaillocker]
crossmenu