Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic documents four previously unknown REVSTEALER modules that linger after the stealer self-destructs, disabling core Windows defences to quietly mine cryptocurrency on compromised endpoints.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.

One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.

The company named the four programs ProManager, WinUpdate, SoftManager, and

Editorial Analysis

Framed for the SOC Analyst desk

Why it matters

REVSTEALER's post-infection modules disable Windows Update and Defender before deploying a cryptominer — understanding these TTPs helps detect lingering persistence after the stealer self-deletes.

What to do

Create detection rules for Defender and Windows Update service tampering events, and hunt for unsigned binaries matching Elastic's published IOCs.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk