Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic documents four previously unknown REVSTEALER modules that linger after the stealer self-destructs, disabling core Windows defences to quietly mine cryptocurrency on compromised endpoints.
Summary written by editorial AI · Source link below
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
The company named the four programs ProManager, WinUpdate, SoftManager, and
Editorial Analysis
The modular post-infection approach — stealer removes itself while persistent payloads disable endpoint defences — complicates forensics and shows commodity malware adopting APT-like persistence tactics.
Deploy tamper-protection for Windows Defender and Windows Update services, and add Elastic's published IOCs to endpoint-detection platforms.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic3d