Find notable cyber news and cases, enriched with sources, timelines, and signals.

REVSTEALER post-self-delete modules for wallet theft and mining

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

REVSTEALER now has four linked Windows modules that persist after self-deletion and keep stealing wallets, hijacking clipboard content, proxying traffic, and mining cryptocurrency. The added modules extend the infection beyond the original stealer and can leave a host active even after the main payload appears gone. One module targets wallet users, another rewrites copied crypto addresses, a third relays attacker traffic through the victim machine, and a fourth disables Windows Update and Microsoft Defender before launching a miner. The broader package is also distributed through game-cheat lures and impersonated software.

Related Happenings

REVSTEALER game-cheat lure campaign on hijacked YouTube channels

Campaign
H score25 First: 06.09.2026 11:34 Last: 06.09.2026 11:34 Sources 1

How related: REVSTEALER reaches victims mainly through game-cheat lures. Elastic identified at least 17 YouTube channels, many of which were hijacked from their original owners, that promoted two cheat websites using short AI-generated videos.

About this happening: The REVSTEALER distribution campaign is still reaching new victims through game-cheat lures, widening exposure across at least 17 hijacked YouTube channels and two che...

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
H score29 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...

Windows cryptocurrency clipper campaign targeting users via USB LNK worms

Campaign
H score32 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...

GlassWorm supply-chain malware activity

Malware Activity
H score22 First: 27.05.2026 14:48 Last: 27.05.2026 14:48 Sources 1

About this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...

Famous Chollima PromptMink supply-chain campaign targeting Web3 developers

Campaign
H score44 First: 29.04.2026 17:43 Last: 29.04.2026 17:43 Sources 1

About this happening: The PromptMink campaign is widening Famous Chollima's supply-chain intrusion playbook by pushing tainted npm packages into developer environments and stealing secrets....

Timeline

  1. 06.09.2026 11:34 2 articles · 3h ago

    Elastic documents REVSTEALER-linked modules that persist after self-deletion

    Initial Disclosure

    Elastic Security Labs documented four Windows programs associated with REVSTEALER—ProManager, WinUpdate, SoftManager, and LockAppHost—that remain on an infected machine after the stealer deletes itself. The modules can steal wallet files and browser wallet extensions, overlay attacker-controlled content on wallet windows, replace copied cryptocurrency addresses, route attacker traffic through the victim connection, and, in the case of LockAppHost, disable Windows Update and Microsoft Defender before launching a cryptocurrency miner.

    Show sources