REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig Crypto Miner
REVSTEALER Infostealer Campaign (TL-2026-2353), also tracked as REF2859, is a high-severity malware campaign, first published 2026-09-02. It has no confirmed attribution, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1027, T1037.001, T1053.005), and is covered by 9 detection rules and 23 indicators of compromise.
Key facts for TL-2026-2353
- Threat ID
- TL-2026-2353
- Also known as
- REF2859
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-09-02
- Last reviewed
- 2026-09-02
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- general, gaming, cryptocurrency
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in REVSTEALER Infostealer Campaign
Malware and tooling: Monero Miner, xmrig, C2 API routes, EtherHiding (Polygon smart contract dead-drop)
Elastic Security Labs (REF2859) and Morphisec report an emerging commercial infostealer, REVSTEALER, distributed via YouTube game-cheat lures and counterfeit software including a fake 'Claude Opus 5 Free Desktop' Electron app. The core stealer exfiltrates browser credentials, cryptocurrency wallets (51+ apps + 225 Chrome extensions), gaming accounts, password managers, and messaging sessions using Chrome App-Bound Encryption bypass and indirect syscalls. Four C2-delivered follow-on modules — ProManager, WinUpdate, SoftManager, and LockAppHost — provide persistent wallet theft, clipboard hijacking, reverse SOCKS5 proxy, and XMRig cryptocurrency mining with defense-evasion capabilities that disable Windows Update services and Microsoft Defender. C2 infrastructure uses Polygon blockchain smart contracts (EtherHiding) for takedown-resistant fallback addressing.
How REVSTEALER Infostealer Campaign works
REVSTEALER is a commercial Windows infostealer first sold on underground forums since at least February 2026, tracked by Elastic Security Labs as REF2859. Over approximately 4,700 samples have been observed on VirusTotal. The malware is distributed primarily through social engineering: at least 17 hijacked YouTube channels post short AI-generated videos advertising free game cheats directing users to cheat websites (elitecheatsx[.]live, resight-cheats[.]net), and a malicious GitHub repository impersonating a 'Claude Opus 5 Free Desktop' application distributed the malware as a trojanized Electron desktop app. Samples are also disguised as legitimate software installers including Slack, qBittorrent, SteelSeries GG, and Blender.
The core REVSTEALER payload is heavily protected with the VMProtect packer and implements extensive anti-analysis measures. A 10-point weighted sandbox-scoring system checks CPU core count, RAM threshold, GPU/PCI vendor, system uptime, process blocklists, username/computer-name blocklists, timing discrepancies, Media Foundation presence, CPUID, and virtualization artifacts; if the total score reaches 7 or higher, the malware self-terminates without executing. It also performs CIS-region language checks on the default system locale and keyboard layout using FNV-1a hashing against a precomputed table of 10 languages (Russian, Ukrainian, Belarusian, Tajik, Armenian, Azerbaijani, Kazakh, Kyrgyz, Turkmen, Uzbek), terminating if a match is found. All Windows API calls are resolved through custom FNV-1a hash lookups with no import table, and the malware uses 14 indirect syscall wrappers to bypass user-mode security-product hooks. A Vectored Exception Handler (VEH) is installed for additional evasion. Unpacked builds present a verification window requiring a random six-character code before execution, a gate designed to hinder automated sandbox analysis.
Once execution proceeds, REVSTEALER performs extensive victim profiling: it collects system information (OS version, CPU, RAM, GPU, hostname, username, locale, timezone, keyboard layout, screen resolution), dumps all environment variables via GetEnvironmentStringsW, enumerates running processes, reads installed applications from the registry, captures clipboard contents, and takes a full-screen screenshot. It then targets a broad range of data sources including browser credential databases (Chromium Login Data and Cookies SQLite databases plus Firefox), Chrome's App-Bound Encryption (bypass achieved by launching the browser in debugger mode, locating App-Bound decryption code, setting a hardware breakpoint, and reading the decrypted key from memory — a technique adapted from the public ChromeKatz/ElevationKatz project), 51+ standalone cryptocurrency wallet applications and 225 Chrome extension identifiers covering wallets and password managers, Windows Credential Manager via CredEnumerateW, Telegram Desktop by scanning all drives for tdata directories and stealing key files enabling full account takeover, Steam local.vdf and loginusers.vdf, Roblox session cookies decrypted via CryptUnprotectData, Minecraft launcher configurations across 8 paths, Battle.net, EA Desktop, Battlestate Games (Escape from Tarkov), messaging apps (Tox, Psi+, Pidgin, Session, Element, Slack) for private keys and chat history, VPN and FTP client configurations, OBS Studio profiles with stream keys, and user-selected documents. Exfiltrated data is LZ77-compressed, tagged with magic-value identifiers, and streamed directly to the C2 server via HTTPS without writing a single archive file to disk. After reporting completion, the core stealer deletes itself with no persistence.
C2 communication uses AES-256-CBC encryption with embedded 32-byte keys and IV-prefixed blobs. The primary C2 endpoint is a hardcoded hostname validated via a GET request to /ext/status that must return 'active'. If the primary server is unreachable, the malware queries up to five public Polygon JSON-RPC endpoints (polygon-bor-rpc.publicnode.com, poly.api.pocket.network, polygon.lava.build, polygon-public.nodies.app, polygon.drpc.org) to read an encrypted fallback C2 address from a Polygon smart contract via eth_call, decrypting it with the embedded AES key. This EtherHiding technique makes C2 infrastructure takedown extremely difficult as operators can rotate endpoints by updating the blockchain contract without rebuilding the malware. Extracted C2 configurations include monitor5.roast-core85[.]click (primary), polygon.iwmukj[.]xyz, polygon.mnyhgxda[.]xyz, static4.livelab[.]one, and meta7[.]archscreen68[.]one. C2 API routes include /ext/status, /ext/sync/ucluv.wkku, /ext/push/ucluv.wkku, /ext/events/ucluv.wkku, and /ext/ping/ucluv.wkku.
Beyond the core stealer, REVSTEALER's C2 infrastructure can deliver four self-contained follow-on modules, each with its own Polygon smart-contract dead-drop address and independent persistence:
1. ProManager (ProManagerServicedc894.exe): Steals wallet files and browser wallet extensions, displays phishing overlays sized and positioned to match target wallet applications, captures passwords typed or pasted into password/passphrase fields, and can deliver additional payloads. Persists via Registry Run key. C2: config.hubdisplay[.]lol, Polygon contract 0x98FF8e7cdC13AE46b83B7590B986F25f1560DF03.
2. WinUpdate (WinUpdate60e3a3.exe): A cryptocurrency clipboard hijacker that monitors clipboard contents and replaces copied cryptocurrency addresses with the attacker's address. Also collects text resembling wallet recovery phrases (mnemonic seeds). Primary persistence via scheduled task with Registry Run key as fallback. CIS language check terminates on 10 languages. C2: health.journal-metric[.]lol, Polygon contract 0x0cF1Ec8B9551103de729c3b02D77221Da9d81Acc.
3. SoftManager (SoftManager72fb40.exe): Implements a reverse SOCKS5 proxy that routes attacker network traffic through the victim's connection over an encrypted WebSocket protocol, providing backconnect access to the compromised host. Persists via logon script, scheduled task, or Registry Run key. CIS language check terminates on 10 languages. C2: metric.gardenpark[.]click, Polygon contract 0x0E04c59f31E382D2B8A1637f4B9A5f04165EC48d.
4. LockAppHost (LockAppHost14a02b.exe): The most disruptive module, deploying the XMRig Monero cryptocurrency miner. It abuses Windows CMSTP (Microsoft Connection Manager Profile Installer) to bypass UAC and gain administrative privileges, falling back to a standard UAC prompt if CMSTP is unavailable. It enables SeDebugPrivilege and uses direct syscall stubs for process manipulation. It disables 5 Windows Update services (UsoSvc, WaaSMedicSvc, wuauserv, BITS, dosvc), 11 scheduled Windows Update tasks, and 2 Windows malware-removal tasks. It adds Microsoft Defender exclusions for common folders and file types by modifying registry keys. The XMRig miner is deployed via process hollowing into suspended instances of svchost.exe or nslookup.exe. On Windows 11 24H2, it patches NtManageHotPatch to bypass Memory Integrity (HVCI) protections. The mining configuration is retrieved from a separate Polygon contract (0xC4eC9B7be1c2A0B39Eca678673DcB9164CA5df53, selector 0x11582022), with the mining pool pointing to pool.supportxmr[.]com:443 with TLS. LockAppHost also continuously monitors running processes every second, pausing XMRig when diagnostic or monitoring tools are detected. It persists via Registry Run key or a Windows service. Crucially, the defense-weakening changes (disabled Windows Update, disabled Defender, removed exclusions) persist even after the miner is detected and removed, requiring manual remediation.
MITRE ATT&CK techniques used in TL-2026-2353
Defense Evasion
T1027 Obfuscated Files or Information; T1055.012 Process Injection: Process Hollowing; T1070.004 Indicator Removal: File Deletion; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
Persistence
T1037.001 Logon Script (Windows); T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Collection
T1056.001 Keylogging; T1113 Screen Capture
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy; T1102.001 Web Service: Dead Drop Resolver; T1573.001 Encrypted Channel: Symmetric Cryptography
Execution
T1106 Native API; T1204.002 User Execution: Malicious File
Impact
Credential Access
T1528 Steal Application Access Token; T1555.003 Credentials from Web Browsers; T1555.004 Credentials from Password Stores: Windows Credential Manager
Privilege Escalation
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
defense-impairment
Affected products and versions in REVSTEALER Infostealer Campaign
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Microsoft — Windows Defender
Vulnerable versions: All versions — exclusions are configurable by design - Microsoft — Chromium (Chrome/Edge/Brave)
Vulnerable versions: All versions with App-Bound Encryption
Remediation for REVSTEALER Infostealer Campaign
Immediate actions
- Re-enable all 5 disabled Windows Update services (UsoSvc, WaaSMedicSvc, wuauserv, BITS, dosvc)
- Re-enable all 11 disabled Windows Update scheduled tasks and 2 malware removal tasks
- Remove all Microsoft Defender exclusions added by LockAppHost
- Terminate XMRig process hidden in suspended svchost.exe or nslookup.exe instances
- Reset all passwords and invalidate all active sessions — password reset alone is insufficient because session cookies and Chrome App-Bound Encryption keys were stolen
- Revoke Telegram and Steam sessions immediately
- Rotate all API keys and OAuth tokens stored in browser sessions
Workarounds
- Block C2 domains at perimeter: monitor5.roast-core85.click, config.hubdisplay.lol, health.journal-metric.lol, metric.gardenpark.click
- Block Polygon JSON-RPC endpoints (polygon-bor-rpc.publicnode.com, poly.api.pocket.network, polygon.lava.build, polygon-public.nodies.app, polygon.drpc.org) for non-browser processes
- Block mining pool pool.supportxmr.com at proxy level
- Restrict CMSTP.exe execution via Windows Defender Application Control or AppLocker
- Blocklist known SHA-256 hashes in EDR and AV solutions
- Educate users to avoid 'free' versions of paid AI software and game cheats from unverified sources
Longer-term hardening
- Deploy EDR with behavioral detection rules for indirect syscall monitoring and process hollowing
- Enable Windows Defender Credential Guard and Application Guard
- Monitor for EthernetHiding C2 traffic patterns (Polygon JSON-RPC queries from non-browser processes)
- Implement YARA rule Windows_Trojan_RevStealer_efc8ff20 across all endpoints
- Enable Elastic prevention rules: Shellcode Execution from Low Reputation Module, VirtualAlloc API Call from Unsigned DLL, Potential Evasion with Hardware Breakpoints
Timeline of REVSTEALER Infostealer Campaign
- REVSTEALER first offered for sale on underground forums as a commercial infostealer; earliest samples begin appearing on VirusTotal
- ChromeKatz/ElevationKatz project published publicly, providing the technique later adapted for REVSTEALER's Chrome App-Bound Encryption bypass
- REVSTEALER distribution campaign escalates with 17+ hijacked YouTube channels posting AI-generated game-cheat lure videos; fake Claude Opus 5 Free Desktop repository created on GitHub
- Morphisec Threat Labs publishes analysis of REVSTEALER distributed via trojanized Electron desktop app impersonating Anthropic's Claude Opus 5
- Help Net Security reports on the fake Claude Opus 5 delivery vector, noting the malware's self-deletion and no-persistence design
- Elastic publishes 9 behavioral prevention rules targeting REVSTEALER techniques including indirect syscalls, process hollowing, hardware breakpoint evasion, and browser process spawning from unusual parents
- Elastic publishes YARA rules (Windows_Trojan_RevStealer_efc8ff20, _0640dc83 for ProManager, _61539fdb for SoftManager, _295fca7e for WinUpdate) and IDAPython string decryption script
- Elastic Security Labs publishes full REF2859 deep-dive identifying ~4,700 VirusTotal samples and documenting four previously undocumented follow-on modules (ProManager, WinUpdate, SoftManager, LockAppHost) with Polygon smart-contract C2 infrastructure
- The Hacker News publishes summary of REVSTEALER campaign, highlighting the four modules and their defense-evasion capabilities
Sources cited for REVSTEALER Infostealer Campaign
- Elastic Security Labs — REVSTEALER ramps up: analysis of up-and-coming credential harvesting infostealer
- Elastic Security Labs — REVSTEALER White Paper (PDF)
- Elastic YARA Rules — Windows_Trojan_RevStealer
- Elastic IDAPython String Decryption Script for REVSTEALER
- The Hacker News — Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
- Morphisec — RevStealer: The Infostealer Built to Leave No Trace
- Help Net Security — Fake Claude Opus 5 app delivers malware and wipes its own tracks
- CyberInsider — New RevStealer malware spreads as fake Claude Opus 5 desktop app
- Cointelegraph — REVSTEALER malware targets crypto wallets via fake AI app
- ChromeKatz / ElevationKatz — public project inspiring REVSTEALER ABE bypass
More in malware
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused Across SectopRAT, MacSync, and AMOS Campaigns
- Rapuncel Infostealer Uses Microsoft-Signed Driver to Kill 145 Security Tools via Fake LastPass Authenticator GitHub Repos
- EtherHiding Malware Abuses Polygon Blockchain to Hide C2 and Steal Banking Credentials
- Jade Sleet (North Korea) Compromises Indian IT Provider via FLATROOF and ROOFDECK macOS Backdoors
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography for Stealth C2
Detection coverage for TL-2026-2353
As of 2026-09-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2353 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.