< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

REVSTEALER modules disable Windows Defender to run crypto miners

Security researchers have identified four new modules associated with the REVSTEALER Windows information stealer. These programs, named ProManager, WinUpdate, SoftManager, and LockAppHost, are designed to remain active on an infected system even after the primary stealer has deleted itself.

According to findings from Elastic Security Labs, these modules function as an “activity set” that installs itself into the user profile to maintain persistence. One specific module, LockAppHost, can gain administrator privileges to disable Windows Update and Microsoft Defender, subsequently running a cryptocurrency miner disguised as a legitimate Windows process.

Other modules target financial data: ProManager is designed to steal wallet files and browser extensions while logging passwords, and WinUpdate can monitor the clipboard to replace copied cryptocurrency addresses with those controlled by attackers. While the core REVSTEALER is known for exfiltrating browser data, passwords, and gaming accounts, these secondary modules ensure continued exploitation after the initial infection appears to have concluded.

Entities

Elastic Security Labs · Microsoft · RevStealer · Windows