Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic documents four previously unknown REVSTEALER modules that linger after the stealer self-destructs, disabling core Windows defences to quietly mine cryptocurrency on compromised endpoints.
Summary written by editorial AI · Source link below
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
The company named the four programs ProManager, WinUpdate, SoftManager, and
Editorial Analysis
Framed for the SOC Analyst desk
REVSTEALER's post-infection modules disable Windows Update and Defender before deploying a cryptominer — understanding these TTPs helps detect lingering persistence after the stealer self-deletes.
Create detection rules for Defender and Windows Update service tampering events, and hunt for unsigned binaries matching Elastic's published IOCs.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic3d