Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Oleh Zai · Let's Make It Easy
Dipublikasikan 2026-09-06
The notable part is the split between the short-lived credential stealer and follow-on modules that establish persistence or secondary activity.
The notable part is the split between the short-lived credential stealer and follow-on modules that establish persistence or secondary activity.
Apa yang dilaporkan
Elastic documented four programs linked to REVSTEALER that remain on an infected Windows machine after the core stealer deletes itself.
The programs are named ProManager, WinUpdate, SoftManager, and LockAppHost.
Detail penting
The primary report says one module disables Windows Update and Microsoft Defender before running a cryptocurrency miner.
Catatan dan batas
The reviewed sources describe the malware family and modules; they do not establish how common every module is across infections.