VMTech
Discuss a project

REVSTEALER-Linked Modules Persist to Disable Windows Defenses

REVSTEALER-Linked Modules Persist to Disable Windows Defenses

Elastic details four persistent programs linked to REVSTEALER

Elastic Security Labs has identified four previously unreported Windows executables associated with the REVSTEALER information stealer: ProManager, WinUpdate, SoftManager and LockAppHost. Unlike the core stealer, which exfiltrates data, reports completion to its server and deletes itself without persistence, the four programs install in the user profile and remain on the compromised device.

LockAppHost is the most disruptive component. Elastic said it can obtain administrator privileges by abusing the Windows CMSTP utility, with a standard elevation prompt as a fallback. It then launches a cryptocurrency miner after weakening Windows Update and Microsoft Defender protections.

Specifically, LockAppHost adds Defender exclusions for common folders and file types, disables five Windows Update services, disables 11 scheduled update tasks and two malware-removal tasks, and hides the miner in legitimate Windows processes. The defensive changes can remain even after the miner has been found.

Shared tradecraft, but no observed delivery chain

Elastic recovered the programs during the same investigation as REVSTEALER and linked them through shared build tradecraft: the same packer, runtime function resolution and Polygon smart contracts used for backup configuration. REVSTEALER can download and execute additional executables from the command line, but Elastic did not see the four programs delivered onto a live REVSTEALER host.

The company therefore describes the set as separate executables rather than plug-ins loaded into the stealer. ProManager steals wallet files and browser wallet extensions, overlays attacker-controlled content on desktop wallet windows, and records credentials typed or pasted into password and passphrase fields. WinUpdate monitors the clipboard, substitutes cryptocurrency addresses and collects text resembling wallet recovery phrases.

SoftManager turns the affected device into a reverse proxy for attacker traffic. The components use different persistence mechanisms, including Registry Run keys, scheduled tasks, logon scripts and, for LockAppHost, a service. Their presence means an incident may continue after the visible information stealer has erased itself.

Broad theft capability and recovery priorities

REVSTEALER has been sold as a commercial infostealer since at least February 2026. Elastic said it targets browser passwords and cookies, data from more than 50 cryptocurrency wallets and wallet extensions, messaging sessions, VPN and FTP settings, Windows Credential Manager entries, password managers and selected documents. It also decrypts stored Roblox session cookies and uses a debugger-based technique to obtain Chrome App-Bound Encryption keys from memory.

Elastic identified game-cheat lures as the main delivery route, including at least 17 YouTube channels promoting two cheat websites with short AI-generated videos. The malware has also appeared in pirated or impersonated software, including a fake Claude Opus 5 Free Desktop application documented by Morphisec. The fake used Anthropic branding, with no indication that Anthropic was compromised.

Elastic published YARA rules, behaviour rules and indicators, although its public YARA file does not include LockAppHost. For businesses responding to a suspected infection, the practical priority is to restore disabled Windows Update services and tasks, remove added Defender exclusions, inspect suspended nslookup.exe or svchost.exe instances for a miner, and revoke active account sessions alongside password changes.

#cybersecurity#windowssecurity#malwareanalysis#endpointsecurity
Open analytics
On the site 2 views
min read 4 06.09.2026
Instagram

REVSTEALER-Linked Modules Persist to Disable Windows Defenses

Open the post on Instagram ↗