Back to News
Cybersecurity

New REVSTEALER Modules Compromise Windows Security to Deploy Crypto Miners

Elastic Security Labs reveals the hidden modules of REVSTEALER that disable key Windows security features to facilitate cryptocurrency mining.

Elastic Security Labs has identified four previously undocumented programs linked to the REVSTEALER Windows information stealer, notably ProManager, WinUpdate, and SoftManager. These modules persist on infected systems even after the main stealer deletes itself, posing significant risks to users. One of the key findings is that these programs disable essential Windows features such as Windows Update and Microsoft Defender, thereby creating a vulnerable environment for the system. This allows the malware to operate undetected while running a cryptocurrency miner, which can lead to performance degradation and increased operational costs for affected organizations.

For businesses, the implications are profound. The ability of malware to disable vital security mechanisms highlights the necessity for enhanced endpoint protection and continuous monitoring solutions. Organizations must prioritize regular security audits and update their defenses to recognize and respond to such emerging threats. This incident underscores the importance of cybersecurity vigilance, especially as cybercriminals increasingly adopt sophisticated tactics that target foundational security measures. As the landscape of threats evolves, integrating advanced AI-driven security solutions will be crucial to mitigate risks associated with information stealers and other malware that exploit system vulnerabilities.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html)*