By Interestana AI Editorial — AI-drafted, human-overseen. How we report
REVSTEALER Modules Disable Windows Security to Mine Crypto

Elastic Security Labs has identified four new malicious programs linked to REVSTEALER, a growing information-stealing malware targeting Windows systems. These programs are designed to persist on an infected machine even after the initial REVSTEALER component has been removed. A key function of one of these persistent modules is to disable critical Windows security features, specifically Windows Update and Microsoft Defender, to create an environment conducive to running a cryptocurrency miner.
The four identified programs are named ProManager, WinUpdate, SoftManager, and another unnamed module. Their primary objective is to ensure the continued operation of a cryptocurrency mining process on the compromised system. By disabling Windows Update, the malware prevents the operating system from automatically patching vulnerabilities or installing security updates that could detect or remove the malicious software. Similarly, disabling Microsoft Defender, Microsoft's built-in antivirus and anti-malware solution, removes a significant layer of protection that would otherwise identify and quarantine the mining software and its associated components.
This tactic of disabling security features is a common strategy employed by malware authors to maintain persistence and maximize the effectiveness of their malicious payloads. REVSTEALER itself is known for its ability to steal sensitive information, such as login credentials, financial data, and other personal details from infected computers. The emergence of these persistent modules suggests an evolution in REVSTEALER's operational tactics, moving beyond simple data exfiltration to include resource hijacking for cryptocurrency mining. This dual-threat approach increases the potential damage to victims, who not only risk data theft but also experience performance degradation and increased electricity consumption due to the cryptocurrency mining operations.
Elastic Security Labs' findings highlight the ongoing threat posed by information stealers and their associated malware families. The ability of these modules to evade detection and disable security mechanisms underscores the importance of robust endpoint security solutions and vigilant user practices. Organizations and individuals are advised to maintain up-to-date security software, exercise caution when opening email attachments or downloading files from untrusted sources, and regularly monitor system performance for any unusual activity that could indicate a compromise. The persistence of these REVSTEALER-linked modules indicates a sophisticated and evolving threat landscape where malware aims to remain undetected for extended periods while executing resource-intensive operations like cryptomining.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.