negativeSYS.SOURCE: The Hacker News• 2026-09-06T14:04:20+05:30
REVSTEALER-Linked Modules Disabling Windows Security to Deploy Cryptocurrency Miner
Four REVSTEALER-linked modules disable Windows Update and Microsoft Defender to deploy a cryptocurrency miner, persisting after the main malware deletes itself. The modules use techniques like CMSTP elevation, Defender exclusion modifications, and EtherHiding to maintain persistence and evade detection.
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
The company named the four programs ProManager, WinUpdate, SoftManager, and
*** END OF TRANSMISSION ***