Security researchers at Elastic Security Labs have discovered four previously undocumented Windows tools linked to the new Revstealer info-stealing malware family.
The tools, named ProManager, WinUpdate, SoftManager, and LockAppHost, remain on infected computers even after Revstealer deletes itself.
LockAppHost can disable Microsoft Defender and Windows Update. It then launches the XMRig cryptocurrency miner hidden inside legitimate Windows processes. The security changes stay in place even after the miner is removed.
ProManager targets cryptocurrency users by placing fake windows over legitimate desktop wallets. It records passwords and passphrases entered by victims, including information pasted from the clipboard.
Revstealer itself collects a wide range of sensitive data, including browser passwords and cookies, cryptocurrency wallets, gaming accounts, messaging data, VPN settings and files. It can also steal Roblox session cookies, allowing attackers to take over accounts without knowing the password.
Revstealer uses several techniques to avoid detection, including sandbox checks, indirect system calls and a backup command server stored through a Polygon blockchain smart contract.
“Despite their distinct roles, all four REVSTEALER modules follow a common design pattern: obfuscated configuration, VMProtect-style protection, and Polygon smart contracts used as dead drops for replaceable settings, including C2 endpoints and XMRig’s command line,” Elastic said.
Elastic said the malware is mainly spread through game-cheat websites and fake or pirated software. Researchers also found evidence of the malware being promoted through hijacked YouTube channels using AI-generated videos.