Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs documented REVSTEALER and four previously unreported companion programs—ProManager, WinUpdate, SoftManager, and LockAppHost—that can remain on infected Windows systems after the main stealer deletes itself. The activity set steals credentials, hijacks crypto transactions, turns victims into a reverse proxy, and can disable Windows Update and Microsoft Defender before dropping a miner, with distribution tied to game-cheat lures and fake software such as the impersonated “Claude Opus 5 Free Desktop” app. #REVSTEALER #ProManager #WinUpdate #SoftManager #LockAppHost #ClaudeOpus5FreeDesktop #Anthropic

Keypoints

  • REVSTEALER deletes itself after stealing data, but the companion modules can stay resident on the machine.
  • ProManager targets crypto wallet users and overlays fake content on wallet windows to capture passwords and passphrases.
  • WinUpdate watches the clipboard and swaps copied cryptocurrency addresses with attacker-controlled addresses.
  • SoftManager converts the victim machine into a reverse proxy for the attacker’s network traffic.
  • LockAppHost disables Windows Update and Microsoft Defender, then runs a cryptocurrency miner with elevated rights.

Read More: https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html