www.elastic.co
Emerging Threat: REVSTEALER Infostealer Targets Credentials and Gaming Accounts
Article Content
REVSTEALER is an emerging infostealer identified by Elastic Security Labs, targeting browsers, wallets, and gaming accounts. It has gained traction since February 2026, with over 4,700 samples reported on VirusTotal. The malware employs social engineering tactics, including fake cheat promotions on YouTube, to lure victims. It features a comprehensive credential harvester and a sandbox scoring system for anti-analysis. Additionally, four associated modules were discovered that disable Windows Update and Microsoft Defender, enhancing the malware's persistence. The modules, named ProManager, WinUpdate, SoftManager, and LockAppHost, remain on infected machines after REVSTEALER deletes itself. This threat is notable for its use of Polygon blockchain technology for infrastructure resilience. The malware's widespread impact includes the theft of sensitive data from various applications and platforms.
Key Points: • REVSTEALER has over 4,700 samples reported on VirusTotal since February 2026. • The malware uses social engineering tactics, including fake cheat promotions on YouTube. • Four associated modules disable critical Windows security features, enhancing persistence.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.