Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-07 ยท updated: 2026-09-07 ยท tags: [incident, revstealer, infostealer, malware, crypto-miner, elastic, persistence] ยท confidence: high ยท severity: high ยท affected_sectors: [enterprise, financial-services, government] ยท au_impact: false

REVSTEALER Modules Disable Windows Update and Defender for Crypto Mining

Elastic Security Labs documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer sold commercially since at least February 2026, which remain on an infected machine after the stealer deletes itself. One switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The findings were published 2 September and freshly surfaced on 6 September.

Summary

The four programs โ€” ProManager, WinUpdate, SoftManager and LockAppHost โ€” respectively steal wallet and browser-extension data, redirect cryptocurrency addresses and capture mnemonic-shaped clipboard content, run a reverse SOCKS5 proxy over an encrypted WebSocket, and deploy XMRig while suspending competitors and establishing persistence. The core stealer exfiltrates browser passwords and cookies, wallets, gaming and messaging data and files. The finding marks a commercial infostealer maturing into a persistent multi-module presence rather than a fire-and-forget credential snatcher.

Impact

  • Persistence survives the stealer's self-deletion โ€” a suspected REVSTEALER hit should be treated as a full reimage, not a cleanup
  • Windows Update and Defender disabled on affected endpoints before a miner is deployed
  • Wallet, credential, browser and messaging data exposure across infected fleets

Sector

Global (Macro)

Sources