REVSTEALER Modules Disable Windows Update and Defender for Crypto Mining
Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer sold commercially since at least February 2026, which remain on an infected machine after the stealer deletes itself. One switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The findings were published 2 September and freshly surfaced on 6 September.
Summary
The four programs โ ProManager, WinUpdate, SoftManager and LockAppHost โ respectively steal wallet and browser-extension data, redirect cryptocurrency addresses and capture mnemonic-shaped clipboard content, run a reverse SOCKS5 proxy over an encrypted WebSocket, and deploy XMRig while suspending competitors and establishing persistence. The core stealer exfiltrates browser passwords and cookies, wallets, gaming and messaging data and files. The finding marks a commercial infostealer maturing into a persistent multi-module presence rather than a fire-and-forget credential snatcher.
Impact
- Persistence survives the stealer's self-deletion โ a suspected REVSTEALER hit should be treated as a full reimage, not a cleanup
- Windows Update and Defender disabled on affected endpoints before a miner is deployed
- Wallet, credential, browser and messaging data exposure across infected fleets
Sector
Global (Macro)
Sources
- Elastic Security Labs โ REVSTEALER ramps up: analysis of up-and-coming infostealer
- raw/digests/Cyber-Digest-2026-09-07.md