← Back to blog

New REVSTEALER Modules Bypass Windows Security to Mine Cryptocurrency

Elastic Security Labs uncovered four persistent modules linked to REVSTEALER that disable Windows Update and Defender. These tools pave the way for stealthy crypto mining operations on compromised systems.

TL;DR

  • Four new REVSTEALER-linked modules remain on infected machines after the initial malware deletes itself
  • One module disables Windows Update and Microsoft Defender to facilitate crypto mining
  • Modules identified as ProManager, WinUpdate, SoftManager, and an unnamed fourth component
  • Attack allows persistent access and stealthy cryptocurrency mining on enterprise endpoints
  • Organizations should monitor for unusual Windows service behavior and unauthorized miner processes

A recent discovery by Elastic Security Labs reveals four previously unknown components associated with REVSTEALER, a rising Windows information-stealing malware. Unlike typical stealers that vanish after data exfiltration, these modules maintain persistence on compromised systems, creating long-term security risks for organizations.

One of these malicious programs specifically targets Windows security infrastructure, disabling both Windows Update and Microsoft Defender services. This strategic move clears the path for deploying cryptocurrency mining software without detection, highlighting a sophisticated evolution in malware persistence techniques.

Technical Breakdown of Persistent Modules

  • Four modules (ProManager, WinUpdate, SoftManager, and unnamed fourth) remain active after REVSTEALER's initial theft phase
  • WinUpdate module specifically disables Windows Update services and Microsoft Defender real-time protection
  • These components establish persistence through legitimate-looking Windows service names to avoid suspicion
  • Crypto mining payload deploys only after security services are confirmed disabled
  • Modules communicate with C2 infrastructure separate from original REVSTEALER operations

Enterprise Security Implications

  • Traditional endpoint detection may miss these modules due to their legitimate service appearance
  • Disabling of Windows Update creates additional vulnerability exposure windows
  • Persistent access enables long-term data theft beyond initial credential harvesting
  • Organizations should implement enhanced monitoring for Windows service creation anomalies
  • Network traffic analysis should flag unauthorized cryptocurrency mining communications

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

New REVSTEALER Modules Bypass Windows Security to Mine Cryptocurrency — Agent Breach Blog | Agent Breach