The Hidden Perils of REVSTEALER Infections

Eradicating a data stealer from a computer does not mean the system is safe. The cybersecurity firm Elastic has outlined four previously unknown components linked to the REVSTEALER credential harvesting infostealer. Unlike the primary malware, which deletes itself after stealing information, these extra programs deeply entrench themselves in Windows. Therefore, they sustain their malicious operations indefinitely.
Credential Harvesting and Browser Evasion
REVSTEALER systematically plunders passwords and session cookies from web browsers. Furthermore, it extracts sensitive data from messaging apps, VPN clients, password managers, and cryptocurrency wallets. To bypass Google Chrome security, the malware launches the browser using a debugger. Consequently, it extracts the App-Bound Encryption key directly from system memory.
Novel Modules and Their Capabilities
These new modules are named ProManager, WinUpdate, SoftManager, and LockAppHost. ProManager steals cryptocurrency wallet files and intercepts passwords. Meanwhile, WinUpdate maliciously swaps copied addresses for cryptocurrency transfers. Additionally, SoftManager turns the compromised machine into a reverse SOCKS5 proxy. Each module uses a unique method to run automatically upon system startup.
The Devastation of LockAppHost
LockAppHost inflicts the most severe damage on the host system. It gains administrative rights through the legitimate CMSTP utility or a standard UAC prompt. Afterward, the module adds exclusions to Microsoft Defender. It also disables five services and eleven Windows Update tasks. Finally, it blocks two operations of the malicious software removal tool. These changes persist even if antivirus software detects the cryptominer.
Next, LockAppHost decrypts XMRig and the WinRing0 driver. It retrieves mining parameters from a Polygon smart contract. Then, it injects its code into a suspended nslookup.exe or svchost.exe process. Moreover, the module actively pauses competing mining operations. It also stops any software that might expose its suspicious network activity.
Attribution and Remediation Strategies
Elastic confidently linked these four programs to REVSTEALER. The connection relies on a shared software packer, identical obfuscation techniques, and overlapping infrastructure. Both threats also utilize Polygon smart contracts. The research team never observed the modules deploying on a machine actively infected by REVSTEALER. Nevertheless, they established this connection through a strong combination of technical evidence.
Following such an infection, specialists advise victims to restore Windows Update services immediately. Users must also delete all unauthorized Defender exclusions. Finally, you should end all active sessions and change your compromised passwords.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.