Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-07 ยท updated: 2026-09-07 ยท tags: [incident, infostealer, rat, persistence, crypto-mining, malware] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: true

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging commercial Windows information stealer sold since at least February 2026. The four modules remain on an infected machine after the core stealer deletes itself, giving the infection a persistent, multi-module presence.

Attribute Detail
Modules ProManager, WinUpdate, SoftManager, LockAppHost
Core stealer Exfiltrates browser passwords/cookies, wallets, gaming and messaging data, files
Persistence Modules survive the stealer's self-deletion
Source Elastic Security Labs โ€” Tier 1/4 (vendor technical analysis)
  • ProManager / WinUpdate โ€” switch off Windows Update and Microsoft Defender before running a cryptocurrency miner; steal wallet and browser-extension data; redirect cryptocurrency addresses and capture mnemonic-shaped clipboard content.
  • SoftManager โ€” runs a reverse SOCKS5 proxy over an encrypted WebSocket.
  • LockAppHost โ€” deploys XMRig while suspending competing miners and establishing persistence.

The findings (published 2 September, freshly surfaced 6 September) point to a commercial infostealer maturing into a persistent multi-module presence rather than a fire-and-forget credential snatcher.

Related Pages

  • Silver Fox โ€” China-linked group operating MODBEACON RAT (infostealer-adjacent)

Source