Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
REVSTEALER Modules Disable Security to Run Crypto Miner

REVSTEALER Modules Disable Security to Run Crypto Miner

Posted on September 6, 2026 By CWS

Elastic Security Labs has identified four new programs linked to the REVSTEALER malware, which is designed to compromise Windows systems by disabling security features and running a cryptocurrency miner. These programs, found on infected machines, persist even after the main malware self-deletes, posing ongoing threats to cybersecurity.

Emergence of REVSTEALER and Its Modules

Initially detected in February 2026, REVSTEALER is a commercial infostealer that extracts sensitive data such as browser passwords, cryptocurrency wallets, and gaming accounts. Once it completes its data exfiltration, it deletes itself, leaving behind no traces. However, four associated programs—ProManager, WinUpdate, SoftManager, and LockAppHost—remain active on the host machine.

ProManager targets cryptocurrency wallet users by overlaying attacker-controlled content on wallet application windows and logging user inputs. WinUpdate replaces copied cryptocurrency addresses with fraudulent ones and collects recovery phrases. SoftManager acts as a reverse proxy, directing network traffic through the victim’s connection.

LockAppHost and Its Disruptive Capabilities

LockAppHost is noted as the most disruptive among the four modules. By disabling Windows Update and Microsoft Defender, it enables a hidden cryptocurrency miner to run with elevated privileges. This program abuses the Windows CMSTP tool to gain admin rights and, if unsuccessful, resorts to standard elevation prompts.

Upon gaining access, LockAppHost modifies system settings by excluding specific folders from Defender’s scans, disabling multiple update and malware removal tasks, and embedding the miner within legitimate processes. These alterations weaken the system’s defenses and persist even after the miner is detected.

Shared Code and Investigation Findings

Elastic’s investigation revealed that the four modules share coding elements with the core REVSTEALER malware, despite not being delivered together. These shared traits include the same packer and runtime function resolution, as well as using Polygon smart contracts for configuration backup.

The modules are categorized as separate executables rather than plugins, emphasizing their independent functionality. This setup allows the modules to operate autonomously, maintaining their presence on the system even after the core malware is removed.

Elastic has released detection rules to help identify and block these threats, but the absence of a rule for LockAppHost highlights the need for vigilance. Users are advised to restore disabled Windows services and remove Defender exclusions if they suspect LockAppHost has been active.

Protecting Against REVSTEALER

To mitigate the risk of infection, users should avoid downloading unofficial software versions and game cheats, as these are common vectors for REVSTEALER distribution. Verified sources should be used for software downloads, and system security settings should be regularly reviewed and updated.

Elastic’s report serves as a comprehensive resource for understanding the capabilities and risks associated with REVSTEALER and its modules. By staying informed and implementing recommended security measures, users can better protect themselves against this evolving cyber threat.

The Hacker News Tags:cryptocurrency miner, Cybersecurity, Elastic Security Labs, Elevated privileges, information stealer, LockAppHost, Malware, malware detection, Polygon blockchain, ProManager, RevStealer, SoftManager, Windows security, WinUpdate, YARA rules

Post navigation

Previous Post: MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
Next Post: Critical Flaw in ASUS Control Center Exposes Systems

Related Posts

LMDeploy Vulnerability Exploited Rapidly After Disclosure LMDeploy Vulnerability Exploited Rapidly After Disclosure The Hacker News
WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide The Hacker News
Firefox Introduces Easy Control to Disable AI Features Firefox Introduces Easy Control to Disable AI Features The Hacker News
Google Launches Android Developer Verification Initiative Google Launches Android Developer Verification Initiative The Hacker News
Critical MetInfo CMS Flaw Exploited for Code Execution Critical MetInfo CMS Flaw Exploited for Code Execution The Hacker News
Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks
  • Urgent Alert: Magento and Adobe Commerce Vulnerability Exploited
  • Magento and Adobe Commerce Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark