Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner Swati KhandelwalSep 06, 2026Malware / Endpoint Security Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and LockAppHost and published the findings on September 2, along with a technical white paper. REVSTEALER has been sold as a commercial infostealer since at least February 2026, when the earliest sample was first detected on VirusTotal. The core stealer exfiltrates browser passwords and cookies, cryptocurrency wallets, gaming…
Original source: thehackernews.com