Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Executive Summary

Elastic Security Labs uncovered four previously unknown modules linked to the REVSTEALER Windows information stealer. The modules—ProManager, WinUpdate, SoftManager, and an unnamed program—persist after the main stealer deletes itself. One module disables Windows Update and Microsoft Defender before launching a cryptocurrency miner, enabling stealthy mining operations.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-06T08:34:20+00:00 - Category: threat-intel

Original Description: Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

"It is only with the heart that one can see rightly, what is essential is invisible to the eye."

— Antoine de Saint-Exupery
Source: The Hacker News