Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact

← Back to insights

Threat Intelligence

REVSTEALER Deploys Persistent Modules That Disable Defender and Launch Crypto Miner

7 September 2026 LetsDefend Infosec 4 min read

Introduction

Elastic Security Labs has identified a significant evolution in the REVSTEALER Windows information stealer. The research reveals four previously undocumented components that remain on a compromised system after the primary stealer self‑deletes. Notably, one of these components disables critical Windows defenses before activating a cryptocurrency miner. This development expands the threat surface and complicates remediation efforts.

What Happened

The investigation documented four programs associated with REVSTEALER: ProManager, WinUpdate, SoftManager, and a fourth, unnamed utility. All four survive the removal of the original stealer, ensuring continued presence on the host. Among them, the WinUpdate module actively disables Windows Update and Microsoft Defender, then launches a crypto‑mining payload. The persistence of these modules indicates a deliberate strategy to maintain foothold and monetize infected machines.

Technical Details

The four modules share a common deployment method: they are dropped onto the system by the initial REVSTEALER payload and registered for automatic execution on boot. ProManager and SoftManager appear to function as management utilities, likely providing remote control capabilities or facilitating further payload delivery. WinUpdate, as its name suggests, targets Windows maintenance services. It modifies registry keys and service configurations to turn off Windows Update, preventing the operating system from receiving critical patches. Simultaneously, it disables Microsoft Defender, the built‑in anti‑malware solution, by altering its real‑time protection settings and stopping the service.

Once defenses are offline, WinUpdate executes a cryptocurrency miner. The miner runs as a background process, consuming CPU cycles and generating hash power for the attacker’s chosen coin. Because the module operates after the stealer has removed itself, traditional detection based on the original REVSTEALER file hash will miss the lingering components. The unnamed fourth program’s functionality remains unclear; its presence suggests additional capabilities that have not yet been publicly disclosed.

Who Is Affected

Any Windows machine that falls victim to the REVSTEALER infection is at risk. The affected product list includes the Windows operating system itself, Microsoft Defender, and Windows Update. Enterprises that rely on default Windows security configurations are particularly vulnerable, as the attack directly targets built‑in defenses. Users who have not applied recent security updates may find the disabling of Windows Update especially damaging, leaving them exposed to further exploits.

Why It Matters

Disabling Windows Update and Microsoft Defender creates a window of opportunity for secondary attacks. Attackers can introduce additional malware, exfiltrate data, or expand the cryptomining operation without interference. The persistence of the modules after the original stealer’s self‑deletion means that incident responders may overlook the residual threat, assuming the infection has been cleared. Moreover, the integration of a crypto miner adds a financial incentive that can drive rapid spread, as miners benefit from large botnets.

Recommended Actions

  1. Immediate Detection – Deploy endpoint detection tools that can identify the four module names (ProManager, WinUpdate, SoftManager) and flag any unknown executable placed in typical installation directories.
  2. Registry and Service Review – Audit registry keys related to Windows Update and Microsoft Defender services. Look for entries that set Start values to 4 (disabled) or modify DisableAntiSpyware flags.
  3. Re‑Enable Defenses – If Windows Update or Defender has been turned off, restore their default settings via Group Policy or PowerShell scripts. Example: Set-MpPreference -DisableRealtimeMonitoring $false.
  4. Process Inspection – Search for high‑CPU processes that match known crypto‑miner signatures. Terminate suspicious miners and capture memory dumps for further analysis.
  5. Full System Scan – Run a comprehensive anti‑malware scan after re‑enabling Defender. Consider using a second opinion scanner to catch remnants that may have evaded the first pass.
  6. Patch Management – Ensure all Windows machines receive the latest security updates. Even though the attacker disables Windows Update, manual patching can close other vulnerabilities that might be leveraged.
  7. Network Monitoring – Monitor outbound traffic for connections to known mining pool addresses. Block suspicious IPs at the firewall level.
  8. Incident Documentation – Record findings, including timestamps of service disablement and miner execution, to aid post‑incident forensics and threat‑intel sharing.

Conclusion

The emergence of persistent modules linked to REVSTEALER marks a shift from a simple information stealer to a multi‑stage threat platform. By disabling Windows Update and Microsoft Defender, the attacker removes critical barriers before turning the host into a crypto‑mining asset. Organizations must adjust detection strategies to look beyond the original stealer file and focus on the ancillary components that remain active. Prompt remediation, reinforced patching, and vigilant monitoring are essential to mitigate this evolving risk.

Sources

  • The Hacker News: https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html
#Threat Intelligence #Malware #Windows #Crypto Mining #Security Labs
Share:
On this page
Introduction What Happened Technical Details Who Is Affected Why It Matters Recommended Actions Conclusion Sources

Have a question about your own security posture?

Related insights
Threat Intelligence
8 Sep 2026 5 min read

PEEP Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors

Researchers have uncovered PEEP, a Chromium‑based post‑exploitation toolkit that masquerades as a bookmarks extension. It injects itself into Chrome and Edge profiles, bypasses store checks, and enables host command execution.

LetsDefend Infosec Read more
Threat Intelligence
8 Sep 2026 4 min read

BigBear 2.0 Phishing‑as‑a‑Service Bypasses MFA at 258 Organizations

A phishing‑as‑a‑service platform dubbed BigBear 2.0 has actively bypassed multi‑factor authentication, stealing over 5,000 Microsoft 365 credentials across 258 victims. This brief outlines the operation, technical approach, impact, and immediate mitigations.

LetsDefend Infosec Read more
Threat Intelligence
8 Sep 2026 4 min read

Microsoft 365 and SaaS Data Theft Campaign Leveraging Help‑Desk Vishing and Token Hijacking

Threat hunters have uncovered a coordinated extortion operation that steals credentials from Microsoft 365 and other SaaS platforms. The group uses help‑desk vishing, in‑the‑middle token theft, and residential‑proxy sign‑ins to target executives, then threatens exposure unless paid.

LetsDefend Infosec Read more

Have a question about your own security posture?

LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.