# REVSTEALER Modules Disrupt Windows Security to Exploit Cryptocurrency Mining

*Published September 7, 2026*
*Source: [https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html](https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/revstealer-modules-disrupt-windows-security-to-exploit-cryptocurrency-mining) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Elastic Security Labs has recently uncovered four previously unknown programs linked to REVSTEALER, a Windows-focused information stealer. These programs, identified as ProManager, WinUpdate, SoftManager, and LockAppHost, remain active on infected devices even after the main stealer has self-deleted. One particularly disruptive module, LockAppHost, disables critical Windows Update and Microsoft Defender features before initiating a cryptocurrency miner. REVSTEALER, active since February 2026, is a commercial infostealer that collects a wide range of sensitive data including browser passwords, cryptocurrency wallet contents, and gaming account information. It operates stealthily by erasing itself after data exfiltration, leaving no trace of its presence. The modules, however, persist by embedding themselves into user profiles.

Elastic Security Labs, which published its findings on September 2, notes that the modules share REVSTEALER's build techniques, such as shared code and configuration methods using Polygon smart contracts. Though they have not observed these modules being deployed directly from a live REVSTEALER instance, the connection is established through shared technical characteristics and investigative context. LockAppHost gains elevated access by exploiting Windows CMSTP, modifies system defenses, and conceals a miner within legitimate processes. Meanwhile, ProManager targets users of desktop cryptocurrency wallets by overlaying attacker-supplied content without affecting the wallet itself.

REVSTEALER reaches victims via deceptive means, including game-cheat lures promoted on hijacked YouTube channels and pirated software disguised as legitimate applications. To avoid detection, it employs advanced evasion techniques and can adapt its operations using a backup command server address stored on the Polygon blockchain. Elastic has provided YARA rules and behavior indicators to help detect and mitigate the threat posed by these modules. Security teams are advised to restore any disabled Windows services, remove exclusions from Microsoft Defender, and monitor for hidden mining processes. Users should also change passwords and end active sessions to ensure account security.
