Advisory
Published 2026-09-02
Verified 2026-09-19

REVSTEALER: Elastic documents four follow-on modules (wallet theft, clipper, proxy, XMRig)

Elastic Security Labs (2 September 2026) analyses REVSTEALER, an emerging Windows infostealer that hides backup C2 addresses in Polygon smart contracts, and documents four follow-on modules delivered by C2 tasking: ProManager (wallet-file and browser-extension theft, phishing overlays, password-aware input capture and payload delivery), WinUpdate (cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (reverse SOCKS5 proxy / backconnect over an encrypted WebSocket), and LockAppHost (XMRig miner deployment, competitor suspension, and persistence). The four modules share obfuscated configuration, VMProtect-style packing, and Polygon dead drops for replaceable settings including C2 endpoints and XMRig command lines. Elastic also covers CIS locale exclusion checks, sandbox scoring, credential harvesting, payload watermarking, and self-deletion. Observed distribution includes game-cheat social engineering — Elastic identified at least 17 YouTube channels promoting elitecheatsx.live and resight-cheats.net — plus builds whose names and metadata impersonate unrelated software (Slack, qBittorrent, SteelSeries GG, Blender, and others). Gen Threat Labs covered the family earlier in 2026. The Hacker News (6 September 2026) summarises the Elastic activity set. Primary: Elastic Security Labs Threat Command report.

Product
Windows (REVSTEALER activity set)
Exploited in Australia?
unknown
Patch to
Hunt with Elastic YARA / protections-artifacts for REVSTEALER; block known lure and C2 domains from the report; treat unexpected wallet overlays, clipper behaviour, and unsolicited XMRig as hostile

Primary: Elastic Security Labs — REVSTEALER (2 Sep 2026) · Vendor: Elastic — REVSTEALER white paper PDF · The Hacker News (6 Sep 2026)

tech identity