discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs documents four programs associated with REVSTEALER, a Windows information stealer, that remain on infected machines after the stealer deletes itself.

By Swati Khandelwal·Sep 6·thehackernews.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Image: thehackernews.com

Elastic Security Labs has found four programs linked to REVSTEALER, a Windows information stealer, that persist on infected machines. One of them disables Windows Update and Defender to run a crypto miner.

Why it matters

This discovery highlights the persistence and sophistication of malware, which can disable critical security features to run malicious activities.

Four programs linked to a bad guy's spyware (REVSTEALER) stay on your computer even after the spyware tries to delete itself. One of these programs stops your computer from getting updates and security checks, so a bad guy can run a coin-making machine.

Analysis

{"heading_1":"The REVSTEALER Infostealer and Its Modules","paragraph_1":"REVSTEALER is an emerging Windows information stealer that has been sold as a commercial product since February 2026. It exfiltrates various types of data and deletes itself after completing the exfiltration process.","paragraph_2":"Elastic Security Labs has documented four additional programs associated with REVSTEALER, which remain on an infected machine after the stealer deletes itself. These programs are named ProManager, WinUpdate, SoftManager, and LockAppHost.","paragraph_3":"ProManager steals wallet files and browser wallet extensions, displays attacker-controlled content over a wallet application's window, and logs passwords typed or pasted into fields it identifies as password or passphrase inputs."}

Key points

  • Elastic Security Labs found four programs linked to REVSTEALER, a Windows information stealer.
  • One of these programs disables Windows Update and Defender to run a crypto miner.
  • REVSTEALER has been sold as a commercial product since February 2026.
The Upside

The discovery of these modules can help improve security measures to detect and prevent such attacks.

The Downside

The persistence of these modules and their ability to disable security features pose a significant threat to computer security.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarewindowscryptoinfostealer

Author

Swati Khandelwal

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 6, 2026

Source

thehackernews.com

Share

Topics

securitymalwarewindowscryptoinfostealer

Related

More from this desk

Sep 5·thehackernews.com

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Security firm Sansec discovers unpatched Magento and Adobe Commerce vulnerability exploited to run malicious code and install backdoor.

Sep 5·thehackernews.com

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains warns Cadence users to revoke and rotate all credentials after attackers exploited a critical vulnerability in TeamCity to breach its environment and extract AWS credentials.

Sep 5·thehackernews.com

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom patches two VMware vulnerabilities with CVSS scores of 9.3 and 8.1, allowing arbitrary code execution and buffer overflow.

Sep 5·bleepingcomputer.com

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked sites deliver ClickFix payloads stored on the BNB Smart Chain (BSC).