RevStealer Is Built to Be Silent
ID: c8e7b14b-cc51-5c64-baa7-5d3782c31695
STIX ID: report--c8e7b14b-cc51-5c64-baa7-5d3782c31695
Feed Name: Morphisec Blog
RevStealer is a stealthy Windows infostealer delivered inside a trojanized Electron application that impersonates legitimate AI software; it collects browser data, credentials, password-manager artifacts and cryptocurrency wallets, exfiltrates them in encrypted records, and self-deletes. The loader and native payload employ extensive anti-analysis and evasion (memory/CPU/GPU checks, timing/debugger checks, vectored exception handlers, importless API resolution, indirect syscalls) and use a Polygon smart contract as a C2 fallback, resulting in short, high-impact thefts that defeat detection-first defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
