RevStealer is a Windows information stealer delivered via a trojanized Electron application distributed on GitHub. The malware employs anti-VM, anti-debugging, and indirect syscall techniques to evade analysis and detection. It exfiltrates data in a single burst and uses a Polygon blockchain smart contract for C2 failover.
Indirect Syscalls
1 post
RevStealer Is Built to Be Silent