Hijacked YouTube channels are pushing an emerging infostealer.
We're tracking
#REVSTEALER: at least 17 compromised channels advertising free game cheats, funneling viewers to 2 malicious domains.
The stealer itself is built for long-term operation:
- Sandbox scoring: 10 weighted checks, self-terminates at a score of 7+
- App-Bound Encryption bypass: reads the decrypted key from browser memory under debugger control
- EtherHiding: fallback C2 stored in a Polygon smart contract, swappable without touching the binary
- Gaming focus: session cookies from Steam, Battlenet, and Roblox, feeding account resale markets
- 4,700 related samples hit VirusTotal in the past year.
Our team observed 4 follow-on modules that haven't been publicly documented until now.
Full analysis, whitepaper, YARA rule, and an IDAPython string decryption tool by
@k33b0i,
@soolidsnakee and
@DanielStepanic:
Blog:
go.es.io/4iJZRQe
Whitepaper:
go.es.io/4xcanmZ