REVSTEALER ramps up: analysis of up-and-coming infostealer
released on 2026-09-06 @ 12:08:53 PM
An emerging infostealer tracked as REVSTEALER under REF2859 has gained significant momentum with approximately 4,700 samples identified over the past year. The malware features comprehensive credential harvesting capabilities targeting browsers, VPN applications, password managers, cryptocurrency wallets, and gaming platforms. It incorporates sophisticated anti-analysis mechanisms including a weighted sandbox scoring system and uses Polygon blockchain-based dead drops for resilient infrastructure management. Distribution occurs primarily through social engineering campaigns targeting gamers via compromised YouTube channels advertising fake game cheats, though samples also impersonate legitimate software like Slack and qBittorrent. The malware delivers four additional modules extending capabilities to include wallet theft, clipboard manipulation, reverse proxy functionality, and cryptocurrency mining deployment. Most samples employ VMProtect packing and feature an App-Bound Encryption bypass using debugger-...