REVSTEALER, an emerging commodity infostealer also tracked as REF2859, is targeting gamers through compromised YouTube channels that promote fraudulent game cheats and mod menus. The malware harvests browser credentials and cookies, messaging and gaming-platform data, documents, screenshots, clipboard contents, and standalone and browser-extension cryptocurrency wallets. It can bypass Chromium App-Bound Encryption by launching browsers under debugger control and extracting data from memory, while VMProtect packing, indirect syscalls, API hashing, CIS locale checks, and sandbox scoring impede analysis.
The malware uses a primary command-and-control server and Polygon smart-contract dead drops to retrieve fallback C2 infrastructure. Its modular ecosystem supports wallet theft, clipboard address hijacking, phishing overlays, SOCKS5 reverse proxying, payload delivery, persistence, and XMRig cryptomining. Auxiliary components—LockAppHost, SoftManager, WinUpdate, and ProManager—can remain after the primary stealer deletes itself, disable Windows security controls, and prolong access, making infected endpoints harder to detect and remediate.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs published an analysis of REVSTEALER, tracked internally as REF2859. The report documented its Polygon smart-contract dead-drop C2 mechanism, cryptocurrency-wallet harvesting, Chromium App-Bound Encryption bypass, and auxiliary modules for phishing overlays, proxying, persistence, clipboard hijacking, and XMRig mining.
REVSTEALER, a Windows information stealer, was reportedly made commercially available. It is designed to steal browser credentials and cookies, messaging data, cryptocurrency-wallet information, files, and gaming-account data.
A REVSTEALER campaign distributed a fake Claude desktop download, ClaudeOpus5-desktop.zip, through the GitHub repository claude5opus/Claude-Opus-5-Free-Desktop. The analyzed Electron-based loader, XabivSystem.exe, could launch a hidden credential stealer and attempted to add the user's AppData directory to Microsoft Defender exclusions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 24 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourcecyberveille.ch
Open sourcecysecurity.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.