The Hidden Perils of REVSTEALER Infections

REVSTEALER malware components architecture and infostealer infection process
Malicious link in a YouTube video description

Eradicating a data stealer from a computer does not mean the system is safe. The cybersecurity firm Elastic has outlined four previously unknown components linked to the REVSTEALER credential harvesting infostealer. Unlike the primary malware, which deletes itself after stealing information, these extra programs deeply entrench themselves in Windows. Therefore, they sustain their malicious operations indefinitely.

Credential Harvesting and Browser Evasion

REVSTEALER systematically plunders passwords and session cookies from web browsers. Furthermore, it extracts sensitive data from messaging apps, VPN clients, password managers, and cryptocurrency wallets. To bypass Google Chrome security, the malware launches the browser using a debugger. Consequently, it extracts the App-Bound Encryption key directly from system memory.

Novel Modules and Their Capabilities

These new modules are named ProManager, WinUpdate, SoftManager, and LockAppHost. ProManager steals cryptocurrency wallet files and intercepts passwords. Meanwhile, WinUpdate maliciously swaps copied addresses for cryptocurrency transfers. Additionally, SoftManager turns the compromised machine into a reverse SOCKS5 proxy. Each module uses a unique method to run automatically upon system startup.

The Devastation of LockAppHost

LockAppHost inflicts the most severe damage on the host system. It gains administrative rights through the legitimate CMSTP utility or a standard UAC prompt. Afterward, the module adds exclusions to Microsoft Defender. It also disables five services and eleven Windows Update tasks. Finally, it blocks two operations of the malicious software removal tool. These changes persist even if antivirus software detects the cryptominer.

Next, LockAppHost decrypts XMRig and the WinRing0 driver. It retrieves mining parameters from a Polygon smart contract. Then, it injects its code into a suspended nslookup.exe or svchost.exe process. Moreover, the module actively pauses competing mining operations. It also stops any software that might expose its suspicious network activity.

Attribution and Remediation Strategies

Elastic confidently linked these four programs to REVSTEALER. The connection relies on a shared software packer, identical obfuscation techniques, and overlapping infrastructure. Both threats also utilize Polygon smart contracts. The research team never observed the modules deploying on a machine actively infected by REVSTEALER. Nevertheless, they established this connection through a strong combination of technical evidence.

Following such an infection, specialists advise victims to restore Windows Update services immediately. Users must also delete all unauthorized Defender exclusions. Finally, you should end all active sessions and change your compromised passwords.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply