REVSTEALER Lures Push Fake Cheats, Drop Miners

The Hacker News · High sophistication
Last updated September 8, 2026

Researchers tied several new programs to the REVSTEALER Windows info-stealer that can steal crypto wallet data, hijack clipboard crypto addresses, and even disable Windows Update and Microsoft Defender to run a crypto miner. Victims are primarily pulled in through “game-cheat” downloads promoted by hijacked YouTube channels and through impersonated/pirated software such as a fake “Claude Opus 5 Free Desktop” app. The write-up includes enough real-world lure and delivery workflow details to build realistic awareness simulations around risky downloads and fake software branding.

How the attack worked

REVSTEALER primarily reaches victims through two lure paths that both rely on trust in familiar-looking content rather than technical exploitation. The first is game-cheat lures: researchers found at least 17 YouTube channels, many hijacked from their original owners, promoting cheat websites through short AI-generated videos. The second is impersonated or pirated software, most notably a fake "Claude Opus 5 Free Desktop" application that copied Anthropic's branding to appear legitimate, even though Anthropic itself was not compromised.

Once a victim downloads and runs the installer, associated modules such as LockAppHost can disable Windows Update services and weaken Microsoft Defender protections before launching a cryptocurrency miner with elevated privileges. Another module, WinUpdate, monitors the clipboard and replaces copied cryptocurrency addresses with attacker-controlled ones while also scanning for recovery phrases.

Why it succeeded

The scheme works because it targets everyday behaviors: gamers looking for an edge and users seeking free access to a paid AI tool. Hijacked YouTube channels lend false credibility to cheat promotion, and copied branding on the fake AI app removes the usual visual cues people rely on to judge legitimacy. Because the core stealer deletes itself after establishing the additional modules, victims may believe the threat is gone even though components remain resident and active.

What to watch for

  • Cheats, cracks, or "free" versions of paid software promoted from unofficial sites or video channels
  • Video-driven urgency or social proof claiming a cheat or tool "works" without independent verification
  • A required executable download for something normally available through an official store or vendor site
  • Unexpected changes to Windows Update settings, Defender exclusions, or scheduled security tasks
  • Cryptocurrency addresses that change unexpectedly after being copied to the clipboard

Building resistance

  • Treat game cheats, cracks, and unofficial "free" versions of paid tools as high risk, and block or avoid installing them on work devices
  • Verify that any software installer comes from the vendor's official channel; copied branding does not confirm authenticity
  • If infection is suspected, end active sessions on accounts rather than assuming a password change alone resolves the risk, since session cookies and encryption keys can be stolen
  • Periodically check that Windows Update and Defender settings have not been silently altered, since some malicious components can persist after the main stealer deletes itself
  • Encourage staff to report suspicious download prompts, especially those tied to gaming content or unexpected "free" versions of popular software

Key findings

  • Elastic documented four previously unreported executables associated with REVSTEALER: ProManager, WinUpdate, SoftManager, and LockAppHost.
  • LockAppHost can disable Windows Update and weaken Microsoft Defender protections before running a cryptocurrency miner with elevated privileges.
  • REVSTEALER infections are driven largely by “game-cheat lures,” including hijacked YouTube channels promoting cheat sites with short AI-generated videos.
  • REVSTEALER has also been distributed as pirated/impersonated software, including a fake “Claude Opus 5 Free Desktop” app using Anthropic branding.
  • WinUpdate replaces copied cryptocurrency addresses in the clipboard with attacker-controlled addresses and looks for recovery phrases.
  • Because the core stealer deletes itself, victims may think the infection is gone while the modules remain resident.

Who’s being targeted

  • Commonly targeted roles: All employees, IT / Helpdesk, Security team, Developers/technical staff, Employees who install software or use crypto wallets.
  • Affected industries: Gaming, Consumer software / end users, Cryptocurrency users.
  • Attack channels: website.
  • Impersonated: Game-cheat provider / cheat download site, Anthropic (Claude desktop app branding).

Red flags to watch for

  • Cheats/cracks promoted as downloads from unofficial sites
  • Video-driven urgency/social proof (“working cheat”) without reputable verification
  • Executable download required for a “cheat” rather than a trusted store install
  • “Free” version of a paid tool from a non-official download channel
  • Branding copied to imply legitimacy
  • Installer not obtained from the vendor’s official site/app store
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does REVSTEALER typically infect victims?

It reaches victims mainly through game-cheat lures, including hijacked YouTube channels that use short AI-generated videos to promote cheat websites. It has also been packaged as pirated or impersonated software, such as a fake Claude Opus 5 Free Desktop app.

What does REVSTEALER do once installed?

Associated modules can disable Windows Update services and weaken Microsoft Defender protections, then run a cryptocurrency miner with elevated privileges. One module also swaps clipboard cryptocurrency addresses and searches for recovery phrases.

Was Anthropic compromised by the fake Claude app?

No. The fake app copied Anthropic's branding to appear legitimate, but there is no indication Anthropic itself was compromised.

Is changing my password enough if I suspect infection?

No. Because the stealer can take session cookies and browser encryption keys, affected users should end active sessions on their accounts rather than assume a password reset alone is sufficient.

Read the video transcript

You’re on YouTube, see a short clip: “New aim-assist cheat, 100% safe, link in description.” You click. The site offers a “ProManager cheat installer.” You run it, thinking it’s just for games, but it’s REVSTEALER. It can grab your crypto wallets, hijack clipboard addresses with WinUpdate, and even drop a miner after LockAppHost weakens Microsoft Defender. Same trick with apps: a site pushing “Claude Opus 5 Free Desktop” using Anthropic branding. Looks polished, but it’s just REVSTEALER in a costume, and the core stealer can delete itself so you think it’s gone while its modules keep running. Aha moment: if a cheat, crack, or “free” Claude desktop app isn’t from an official store or the vendor’s own site, treat it as REVSTEALER. Your move: don’t install it, report the link to IT and walk away.

Similar attacks

Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Planted Text Tricks AI Agents Into Bad Clicks

Planted Text Tricks AI Agents Into Bad Clicks

Researchers demonstrated a new “agent data injection” technique where attackers plant content (like a review or GitHub comment) that an AI agent mistakenly treats as trusted system data. In tests, this caused web-browsing agents to click the wrong buttons (e.g., “Buy Now”) and coding agents to run…

July 16, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026