Elastic Security Labs has identified four new programs linked to the REVSTEALER malware, which is designed to compromise Windows systems by disabling security features and running a cryptocurrency miner. These programs, found on infected machines, persist even after the main malware self-deletes, posing ongoing threats to cybersecurity.
Emergence of REVSTEALER and Its Modules
Initially detected in February 2026, REVSTEALER is a commercial infostealer that extracts sensitive data such as browser passwords, cryptocurrency wallets, and gaming accounts. Once it completes its data exfiltration, it deletes itself, leaving behind no traces. However, four associated programs—ProManager, WinUpdate, SoftManager, and LockAppHost—remain active on the host machine.
ProManager targets cryptocurrency wallet users by overlaying attacker-controlled content on wallet application windows and logging user inputs. WinUpdate replaces copied cryptocurrency addresses with fraudulent ones and collects recovery phrases. SoftManager acts as a reverse proxy, directing network traffic through the victim’s connection.
LockAppHost and Its Disruptive Capabilities
LockAppHost is noted as the most disruptive among the four modules. By disabling Windows Update and Microsoft Defender, it enables a hidden cryptocurrency miner to run with elevated privileges. This program abuses the Windows CMSTP tool to gain admin rights and, if unsuccessful, resorts to standard elevation prompts.
Upon gaining access, LockAppHost modifies system settings by excluding specific folders from Defender’s scans, disabling multiple update and malware removal tasks, and embedding the miner within legitimate processes. These alterations weaken the system’s defenses and persist even after the miner is detected.
Shared Code and Investigation Findings
Elastic’s investigation revealed that the four modules share coding elements with the core REVSTEALER malware, despite not being delivered together. These shared traits include the same packer and runtime function resolution, as well as using Polygon smart contracts for configuration backup.
The modules are categorized as separate executables rather than plugins, emphasizing their independent functionality. This setup allows the modules to operate autonomously, maintaining their presence on the system even after the core malware is removed.
Elastic has released detection rules to help identify and block these threats, but the absence of a rule for LockAppHost highlights the need for vigilance. Users are advised to restore disabled Windows services and remove Defender exclusions if they suspect LockAppHost has been active.
Protecting Against REVSTEALER
To mitigate the risk of infection, users should avoid downloading unofficial software versions and game cheats, as these are common vectors for REVSTEALER distribution. Verified sources should be used for software downloads, and system security settings should be regularly reviewed and updated.
Elastic’s report serves as a comprehensive resource for understanding the capabilities and risks associated with REVSTEALER and its modules. By staying informed and implementing recommended security measures, users can better protect themselves against this evolving cyber threat.
