REVSTEALER Modular Information Stealer and Persistence Modules
REVSTEALER is an emerging information stealer that drops modular components capable of persistence, credential theft, clipboard hijacking, and stealthy cryptocurrency mining while disabling security controls.
REVSTEALER is a commercial information stealer detected in the wild since February 2026, primarily distributed via malicious game-cheat lures and impersonated AI applications. While the core stealer exfiltrates credentials, browser data, and wallet files before self-deleting, it is often associated with four post-exploitation modules: ProManager, WinUpdate, SoftManager, and LockAppHost. These modules persist in the user profile to perform secondary malicious actions.
Most notably, LockAppHost achieves administrative persistence by abusing the CMSTP tool to disable Windows Update services and Microsoft Defender features. It subsequently deploys a cryptocurrency miner masked within system processes. These modules share tradecraft with the core stealer, including indirect system calls, packer-based obfuscation, and the use of Polygon smart contracts for resilient command-and-control communication. Organizations should prioritize detection of these persistent modules, as the primary stealer may have already completed its execution before security teams identify the compromise.
Attack Chain
- Initial delivery of REVSTEALER via malicious game-cheat lures or impersonated software installers.
- Execution of the core stealer using indirect syscalls and anti-sandbox checks to evade security analysis.
- Exfiltration of credentials, cookies, and sensitive session data to the primary C2 or blockchain-based backup.
- Deployment of persistent secondary modules (e.g., LockAppHost) into the user profile.
- Elevation of privileges using CMSTP abuse to gain administrative rights.
- Disabling of Windows Update services and modification of Microsoft Defender exclusions to weaken system defenses.
- Execution of a hidden cryptocurrency miner within a suspended instance of legitimate processes like nslookup.exe or svchost.exe.
- Long-term persistence maintained via Registry Run keys or scheduled tasks for secondary modules.
Impact
Successful infection results in the total loss of credentials, browser cookies, cryptocurrency wallet contents, and messaging data. The persistence modules enable long-term resource hijacking through cryptocurrency mining and proxying, while the weakened security state leaves the machine susceptible to subsequent opportunistic exploitation. Observed activity includes thousands of samples detected in the wild, indicating high-volume distribution targeting end users.
Recommendation
- Deploy Sigma rules to monitor for unauthorized execution of cmstp.exe for privilege escalation.
- Hunt for persistence artifacts associated with the identified modules, specifically Registry Run keys and scheduled tasks that execute unsigned binaries in user profile directories.
- Monitor for Windows Update service status changes or unusual Defender exclusion modifications.
- Inspect suspended processes (nslookup.exe, svchost.exe) for unexpected malicious threads or memory-resident payloads consistent with crypto-mining.
- Require password resets and session revocation for any accounts identified on compromised machines due to the theft of session cookies and browser secrets.
Immediate actions
Block identified C2 domains at DNS resolver
Deploy Sigma rule for CMSTP execution
Threat Hunt
Search for unknown processes executing out of user profile directories
Data: Process creation logs with full path
Mitigations
Remove unauthorized Microsoft Defender exclusions
LockAppHost modules
Detection coverage 1
Detect CMSTP Execution for Privilege Escalation
highDetects the use of the Connection Manager Profile Installer (cmstp.exe) to execute remote script files, a common technique for bypass/elevation.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
4
domain
5
hash_sha256
| Type | Value |
|---|---|
| hash_sha256 | adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 |
| hash_sha256 | 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa |
| hash_sha256 | 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb |
| hash_sha256 | 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 |
| hash_sha256 | c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 |
| domain | monitor5.roast-core85.click |
| domain | config.hubdisplay.lol |
| domain | health.journal-metric.lol |
| domain | metric.gardenpark.click |