RevStealer is a commercially distributed Windows infostealer active since at least February 2026. It harvests browser passwords, cookies and session data, browser-extension storage, Windows Credential Manager data, password-manager records, cryptocurrency-wallet material, VPN and remote-access credentials, messaging and gaming-platform data, screenshots, clipboard contents, system information, and selected user documents. It can bypass Chromium App-Bound Encryption by running a browser under debugger control and recovering the decrypted key from process memory. Collected information is encrypted and transmitted incrementally to command-and-control infrastructure, after which the core stealer deletes itself rather than establishing persistence. RevStealer uses runtime API resolution, indirect system calls, encrypted strings and configuration, virtual-machine and sandbox scoring, regional locale exclusions, and other anti-analysis controls. It can use Polygon smart contracts as EtherHiding-style dead drops to retrieve fallback command-and-control configuration. Distribution has relied on social-engineering lures aimed at gamers, including compromised YouTube channels promoting fraudulent game cheats and mod menus, as well as trojanized applications impersonating legitimate software and a fake Claude desktop application. Associated components can provide cryptocurrency-wallet overlay phishing and input capture, clipboard cryptocurrency-address replacement, reverse SOCKS5 proxy access, and cryptomining with persistence and security-control weakening. No public attribution to a specific threat actor is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The loader used "an encrypted resources\app-ri9icle2.res" and the guidance says not to "decrypt its resource or recover the native payload."
"ClaudeOpus5-desktop.zip is the name of a fake Claude download documented in a RevStealer campaign" and the lure was traced to a Claude-themed GitHub repository.
La section « TTPs et IOCs détectés » identifie explicitement « T1070.004 — Indicator Removal: File Deletion ».
Le malware évalue CPU, RAM, GPU/PCI vendor, uptime, CPUID, virtualisation, Media Foundation, processus et noms d'utilisateur avant de s'auto-terminer selon son score sandbox.
Victim profiling includes collecting all running processes; the sandbox scoring system also uses a process blocklist.
Les contrôles anti-analyse portent notamment sur « nombre de cœurs CPU, RAM, GPU/PCI vendor, uptime, CPUID, virtualisation » ainsi que sur la liste de processus et les applications installées.
« Collecte de documents, fichiers de configuration » et recherche de fichiers de configuration de clients de jeu, wallets et applications ciblées dans des chemins spécifiques.
Le malware évalue CPU, RAM, GPU/PCI vendor, uptime, CPUID, virtualisation, Media Foundation, processus et noms d'utilisateur avant de s'auto-terminer selon son score sandbox.
Le système anti-analyse comprend des « timing checks » et s'auto-termine lorsque le score sandbox pondéré est supérieur ou égal à 7.
Victim profiling collects all installed applications via the Windows uninstall registry key path SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-stealing malware family delivered through a fake Claude desktop-download lure. The analyzed Electron loader can launch a hidden stealer and attempts to add the user AppData directory to Microsoft Defender exclusions. Elastic documented credential harvesting and additional modules that may extend the incident.
Infostealer distributed through social-engineering campaigns, particularly fake game cheats and mod menus. It evades analysis, avoids CIS locales, steals browser-extension and standalone-wallet credentials, application data, documents, clipboard contents, screenshots, and gaming-platform data. It bypasses Chrome App-Bound Encryption through debugger-controlled browser execution and memory access, and uses Polygon smart-contract dead drops to obtain fallback C2 infrastructure.
A commercial Windows information stealer that harvests browser cookies and passwords, messaging data, cryptocurrency-wallet data, files, and gaming accounts. It uses a wallet-harvesting architecture to identify and collect wallet-specific files, then deletes itself after theft.
Windows infostealer that exfiltrates browser passwords and cookies, cryptocurrency-wallet data, messaging sessions, VPN/FTP configurations, Credential Manager data, password-manager data, selected documents, and gaming credentials. It can download and execute additional payloads, evades analysis, uses indirect system calls, and retrieves backup C2 configuration through Polygon smart contracts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.