Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic documents four previously unknown REVSTEALER modules that linger after the stealer self-destructs, disabling core Windows defences to quietly mine cryptocurrency on compromised endpoints.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.

One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.

The company named the four programs ProManager, WinUpdate, SoftManager, and

Editorial Analysis

Why it matters

The modular post-infection approach — stealer removes itself while persistent payloads disable endpoint defences — complicates forensics and shows commodity malware adopting APT-like persistence tactics.

What to do

Deploy tamper-protection for Windows Defender and Windows Update services, and add Elastic's published IOCs to endpoint-detection platforms.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk