INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

RevStealer Disables Windows Update and Defender for Crypto Miner

| 2026-09-04 19:28 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
A sophisticated cyberattack, attributed to the Silence APT group, has been uncovered targeting systems in Russia and Central Asia. The attack leverages four previously unreported programs associated with RevStealer, a Windows information stealer, which remain on an infected machine after the stealer deletes itself. These programs disable Windows Update and Microsoft Defender before running a cryptocurrency miner, compromising system security. The attackers also abuse the Windows CMSTP tool to gain administrator rights, adding exclusions for common folders and file types, disabling update services, and hiding malware within legitimate processes. This incident highlights the evolving threat landscape in Russia and Central Asia, with targeted sectors including finance, healthcare, manufacturing, and technology.
Technical Mitigations AI-generated
• Implement a robust Windows Defender configuration to exclude common cryptocurrency addresses from being copied to the clipboard. • Regularly review and update system registry settings, including Registry Run keys, to prevent malicious programs like LockAppHost from running with administrator rights. • Utilize a reputable anti-malware solution that can detect and remove malware, such as ProManager and SoftManager, which are designed to turn the machine into a reverse proxy or run cryptocurrency miners.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

13d723••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
6e1e9d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c66d2b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
0e2182••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
mo•••••.click
en•••••.com
me•••••.one
me•••••.click
ns•••••.exe
sv•••••.exe
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SilenceSilence Lumma StealerLumma Stealer
Target & Sectors
CENTRAL_ASIA CENTRAL_ASIA cryptocurrencycryptocurrency healthhealth
Incident Timeline
‎at least February 2026
Threat actors sold REVSTEALER as a commercial infostealer since at least February 2026.
organisation VirusTotal
‎March 2026
Threat actors using the RevStealer and VoidStealer stealers likely adapted Elastic's ElevationKatz project in March 2026.
organisation VoidStealer
‎August 31
Threat actors packaged pirated software, including a fake "Claude Opus 5 Free Desktop" application, to distribute the RevStealer malware.
general_metric 5 supposed application
organisation Morphisec
‎September 2
Threat actors used ProManager, WinUpdate, SoftManager, and LockAppHost to target a company.
organisation ProManager
organisation WinUpdate
organisation SoftManager
‎2026/09/04
Threat actors used a lure impersonating Anthropic's Claude desktop software to target victims, who were then infected with the RevStealer malware.
infrastructure Windows
organisation Electron
organisation GitHub
organisation Microsoft Defender
organisation AES
organisation RevStealer
organisation Windows Update
organisation Microsoft Defender Registry Run
organisation Microsoft
organisation Telegram
organisation FTP
threat_actor Silence
organisation Elastic
organisation Registry Run
organisation Logon
organisation ProManager C2
organisation WinUpdate C2
organisation SHA-256
organisation Polygon
organisation App-Bound Encryption
organisation AuraStealer
organisation YARA
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Intelligence Sources