Emerging Threat: REVSTEALER Infostealer Targets Credentials and Gaming Accounts

Emerging Threat: REVSTEALER Infostealer Targets Credentials and Gaming Accounts

First seen 6 Sep 2026, 10:19 UTC Thehackernewswww.elastic.co 64.5

Article Content

Browse articles
ThreatCluster

REVSTEALER is an emerging infostealer identified by Elastic Security Labs, targeting browsers, wallets, and gaming accounts. It has gained traction since February 2026, with over 4,700 samples reported on VirusTotal. The malware employs social engineering tactics, including fake cheat promotions on YouTube, to lure victims. It features a comprehensive credential harvester and a sandbox scoring system for anti-analysis. Additionally, four associated modules were discovered that disable Windows Update and Microsoft Defender, enhancing the malware's persistence. The modules, named ProManager, WinUpdate, SoftManager, and LockAppHost, remain on infected machines after REVSTEALER deletes itself. This threat is notable for its use of Polygon blockchain technology for infrastructure resilience. The malware's widespread impact includes the theft of sensitive data from various applications and platforms.

Key Points: • REVSTEALER has over 4,700 samples reported on VirusTotal since February 2026. • The malware uses social engineering tactics, including fake cheat promotions on YouTube. • Four associated modules disable critical Windows security features, enhancing persistence.

Ask AI about this cluster

Timeline

2026-02-01
First REVSTEALER sample detected
The earliest sample of REVSTEALER was identified on VirusTotal, marking its emergence as a threat.
Thehackernews
2026-09-02
Four REVSTEALER modules documented
Elastic Security Labs published findings on four previously unreported programs linked to REVSTEALER.
Thehackernews
2026-09-06
Elastic Security Labs releases detailed analysis
A comprehensive report on REVSTEALER's distribution, features, and infrastructure was published.
Elastic Security Labs