RevStealer Infostealer Uses Anti-Analysis Checks and Polygon C2 Failover

Summary
Morphisec researchers describe RevStealer, a Windows infostealer delivered through trojanized Electron apps. It uses anti-analysis checks, indirect system calls and Polygon-based C2 failover to steal sensitive data and evade detection.
Key points
- RevStealer is distributed through GitHub repositories and game-cheat-themed sites, including a fake Claude-branded desktop app.
- Its Electron loader checks host resources and characteristics before decrypting and launching a hidden native payload.
- The malware targets browser data, credentials, password managers, cryptocurrency wallets, VPN accounts, clipboard contents and other user information.
- It uses indirect system calls, anti-VM checks and a CAPTCHA gate to hinder monitoring and automated analysis.
- If its primary command server is unreachable, it retrieves a fallback address from a Polygon smart contract.
- RevStealer streams stolen data, deletes staging files and has no persistence, leaving little time for response after execution.
Article Details
- Attack Vectors
- RevStealer is distributed through GitHub repositories and game-cheat-themed sites, including a fake “Claude Opus 5 Free Desktop” repository that impersonates Anthropic.
- A trojanized Electron application checks host characteristics and debugger timing before decrypting an embedded AES-256-CBC native payload, writing it under AppData and launching it hidden.
- The native payload uses anti-VM checks, language-based exclusions and a CAPTCHA gate before collecting credentials, browser data, cryptocurrency wallet material and other user data.
- RevStealer exfiltrates encrypted typed records. If its primary C2 server is unreachable, it queries a Polygon smart contract for a replacement address.
- Defensive Notes
- The loader attempts to add the user's AppData folder to Microsoft Defender's exclusion list.
- The article reports no persistence mechanism and describes a short theft session followed by self-deletion.
- Morphisec advocates pre-execution prevention through Automated Moving Target Defense (AMTD) and describes infiltration protection, decoy credentials, impact protection and exposure management as defensive measures.
MITRE ATT&CK
T1027.007 · Dynamic API ResolutionThe native payload resolves Windows APIs without an import table.T1036 · MasqueradingThe trojanized desktop application impersonates legitimate software, and a distribution repository uses Claude branding while impersonating Anthropic.T1070.004 · File DeletionThe article reports that RevStealer deletes itself after its short theft session; the loader also attempts to delete its staging file.T1113 · Screen CaptureRevStealer captures screenshots.T1115 · Clipboard DataRevStealer collects clipboard contents.T1140 · Deobfuscate/Decode Files or InformationAfter its environment checks pass, the loader decrypts an embedded AES-256-CBC resource containing the native payload.T1497.001 · System ChecksThe loader checks memory, CPU cores and graphics hardware, while the native payload applies a weighted anti-VM score to avoid analysis environments.T1539 · Steal Web Session CookieRevStealer collects browser session cookies.T1555.003 · Credentials from Web BrowsersRevStealer collects browser databases and encryption keys to obtain stored browser credentials.T1555.004 · Windows Credential ManagerWindows Credential Manager is among RevStealer's confirmed collection targets.T1562.001 · Disable or Modify ToolsThe loader attempts to add the user's AppData folder to Microsoft Defender's exclusion list.T1614.001 · System Language DiscoveryThe native stage checks language settings and terminates on Russian, Ukrainian and several Central Asian settings.T1622 · Debugger EvasionThe Electron loader times a JavaScript debugger statement and wipes its encoded string table if execution pauses for roughly 100 milliseconds.
People
Malware
Vendors
Products
GitHubMorphisec Threat Labs observed it distributed through GitHub repositories and game-cheat-themed sites, with the most notable lure a fake “Claude Opus 5 Free Desktop” project that impersonates Anthropic and advertisesMicrosoft Defendernative payload inside an application resource, attempts to add the user’s AppData folder to Microsoft Defender’s exclusion list, and launches the payload with no visible window.Microsoft WindowsRevStealer is a Windows information stealer delivered inside a trojanized Electron desktop application that impersonates legitimate software.Morphisec Anti-Ransomware Assurance SuiteThe Morphisec Anti-Ransomware Assurance Suite extends this across the chain.PolygonIf the primary C2 is unreachable, RevStealer reads a fallback address from a smart contract on the Polygon blockchain, letting operators rotate infrastructure without rebuilding the malware.