RevStealer Infostealer Uses Anti-Analysis Checks and Polygon C2 Failover

· Original article ↗

Summary

Morphisec researchers describe RevStealer, a Windows infostealer delivered through trojanized Electron apps. It uses anti-analysis checks, indirect system calls and Polygon-based C2 failover to steal sensitive data and evade detection.

Key points

  • RevStealer is distributed through GitHub repositories and game-cheat-themed sites, including a fake Claude-branded desktop app.
  • Its Electron loader checks host resources and characteristics before decrypting and launching a hidden native payload.
  • The malware targets browser data, credentials, password managers, cryptocurrency wallets, VPN accounts, clipboard contents and other user information.
  • It uses indirect system calls, anti-VM checks and a CAPTCHA gate to hinder monitoring and automated analysis.
  • If its primary command server is unreachable, it retrieves a fallback address from a Polygon smart contract.
  • RevStealer streams stolen data, deletes staging files and has no persistence, leaving little time for response after execution.

Article Details

Attack Vectors
  • RevStealer is distributed through GitHub repositories and game-cheat-themed sites, including a fake “Claude Opus 5 Free Desktop” repository that impersonates Anthropic.
  • A trojanized Electron application checks host characteristics and debugger timing before decrypting an embedded AES-256-CBC native payload, writing it under AppData and launching it hidden.
  • The native payload uses anti-VM checks, language-based exclusions and a CAPTCHA gate before collecting credentials, browser data, cryptocurrency wallet material and other user data.
  • RevStealer exfiltrates encrypted typed records. If its primary C2 server is unreachable, it queries a Polygon smart contract for a replacement address.
Defensive Notes
  • The loader attempts to add the user's AppData folder to Microsoft Defender's exclusion list.
  • The article reports no persistence mechanism and describes a short theft session followed by self-deletion.
  • Morphisec advocates pre-execution prevention through Automated Moving Target Defense (AMTD) and describes infiltration protection, decoy credentials, impact protection and exposure management as defensive measures.

MITRE ATT&CK

T1027.007 · Dynamic API ResolutionThe native payload resolves Windows APIs without an import table.T1036 · MasqueradingThe trojanized desktop application impersonates legitimate software, and a distribution repository uses Claude branding while impersonating Anthropic.T1070.004 · File DeletionThe article reports that RevStealer deletes itself after its short theft session; the loader also attempts to delete its staging file.T1113 · Screen CaptureRevStealer captures screenshots.T1115 · Clipboard DataRevStealer collects clipboard contents.T1140 · Deobfuscate/Decode Files or InformationAfter its environment checks pass, the loader decrypts an embedded AES-256-CBC resource containing the native payload.T1497.001 · System ChecksThe loader checks memory, CPU cores and graphics hardware, while the native payload applies a weighted anti-VM score to avoid analysis environments.T1539 · Steal Web Session CookieRevStealer collects browser session cookies.T1555.003 · Credentials from Web BrowsersRevStealer collects browser databases and encryption keys to obtain stored browser credentials.T1555.004 · Windows Credential ManagerWindows Credential Manager is among RevStealer's confirmed collection targets.T1562.001 · Disable or Modify ToolsThe loader attempts to add the user's AppData folder to Microsoft Defender's exclusion list.T1614.001 · System Language DiscoveryThe native stage checks language settings and terminates on Russian, Ukrainian and several Central Asian settings.T1622 · Debugger EvasionThe Electron loader times a JavaScript debugger statement and wipes its encoded string table if execution pauses for roughly 100 milliseconds.

People

Malware

Vendors

Products

Related Articles