INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
RevStealer Disables Windows Update and Defender for Crypto Miner
| 2026-09-04 19:28 CRITICAL HIGH MALWARE & BOTNETS
Executive Summary
AI-generated
A sophisticated cyberattack, attributed to the Silence APT group, has been uncovered targeting systems in Russia and Central Asia. The attack leverages four previously unreported programs associated with RevStealer, a Windows information stealer, which remain on an infected machine after the stealer deletes itself. These programs disable Windows Update and Microsoft Defender before running a cryptocurrency miner, compromising system security. The attackers also abuse the Windows CMSTP tool to gain administrator rights, adding exclusions for common folders and file types, disabling update services, and hiding malware within legitimate processes. This incident highlights the evolving threat landscape in Russia and Central Asia, with targeted sectors including finance, healthcare, manufacturing, and technology.
Technical Mitigations AI-generated
• Implement a robust Windows Defender configuration to exclude common cryptocurrency addresses from being copied to the clipboard.
• Regularly review and update system registry settings, including Registry Run keys, to prevent malicious programs like LockAppHost from running with administrator rights.
• Utilize a reputable anti-malware solution that can detect and remove malware, such as ProManager and SoftManager, which are designed to turn the machine into a reverse proxy or run cryptocurrency miners.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
13d723••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
6e1e9d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c66d2b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
0e2182••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
mo•••••.click
en•••••.com
me•••••.one
me•••••.click
ns•••••.exe
sv•••••.exe
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SilenceSilence
Lumma StealerLumma Stealer
Target & Sectors
CENTRAL_ASIA
CENTRAL_ASIA
cryptocurrencycryptocurrency
healthhealth
Incident Timeline
at least February 2026
Threat actors sold REVSTEALER as a commercial infostealer since at least February 2026.
Click on any entity below to view its context and source!
organisation
VirusTotal
REVSTEALER has been sold as a commercial infostealer since at least February 2026, when the earliest sample was first detected on VirusTotal.
March 2026
Threat actors using the RevStealer and VoidStealer stealers likely adapted Elastic's ElevationKatz project in March 2026.
Click on any entity below to view its context and source!
organisation
VoidStealer
Elastic said it was likely adapted from the public ElevationKatz project and was also used by another stealer,
VoidStealer, in March 2026
.
August 31
Threat actors packaged pirated software, including a fake "Claude Opus 5 Free Desktop" application, to distribute the RevStealer malware.
Click on any entity below to view its context and source!
general_metric
5 supposed application
The malware has also been packaged as pirated or impersonated software, including a fake "Claude Opus 5 Free Desktop" application that
Morphisec documented
on August 31.
organisation
Morphisec
The malware has also been packaged as pirated or impersonated software, including a fake "Claude Opus 5 Free Desktop" application that
Morphisec documented
on August 31.
September 2
Threat actors used ProManager, WinUpdate, SoftManager, and LockAppHost to target a company.
Click on any entity below to view its context and source!
organisation
ProManager
The company named the four programs
ProManager
,
WinUpdate
,
SoftManager
, and
LockAppHost
and
published the findings on September 2
, along with a
technical white paper
.
organisation
WinUpdate
The company named the four programs
ProManager
,
WinUpdate
,
SoftManager
, and
LockAppHost
and
published the findings on September 2
, along with a
technical white paper
.
organisation
SoftManager
The company named the four programs
ProManager
,
WinUpdate
,
SoftManager
, and
LockAppHost
and
published the findings on September 2
, along with a
technical white paper
.
2026/09/04
Threat actors used a lure impersonating Anthropic's Claude desktop software to target victims, who were then infected with the RevStealer malware.
Click on any entity below to view its context and source!
infrastructure
Windows
RevStealer is a Windows information stealer distributed through trojanized Electron applications hosted on GitHub repositories and game-cheat-themed websites.
It attempts to add the user’s AppData directory to Microsoft Defender exclusions, decrypts an embedded native executable using AES-CBC, launches it with hidden windows, and deletes the temporary payload when possible.
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner.
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
…the machine into a reverse proxy that routes the attacker's network traffic through the victim's connection
Logon script, scheduled task, or Registry Run key
LockAppHost
Runs a cryptocurrency miner with administrator rights after disabling Windows Update and excluding folders from Microsoft Defender
Registry Run key or a service
LockAppHost is the most disruptive of the four.
To gain administrator rights, it abuses the Windows CMSTP tool, falling back to a standard elevation prompt if that fails.
Once elevated, it adds Microsoft Defender exclusions for common folders and file types, disables 5 Windows Update services, disables 11 scheduled update tasks and 2 malware removal tasks, and then hides a miner within legitimate Windows processes.
It collects browser passwords and cookies; files from more than 50 cryptocurrency wallets and a large set of wallet browser extensions; session data from Telegram and other messaging clients; VPN and FTP configuration; the Windows Credential Manager; password managers; and selected documents.
It resolves Windows functions without a normal import table and calls the kernel via indirect system calls to bypass the hooks installed by security products.
Where LockAppHost has run, responders should re-enable the Windows Update services and scheduled tasks that it turned off, remove the Microsoft Defender exclusions it added, and look for a miner hidden in a suspended instance of nslookup.exe or svchost.exe.
organisation
Electron
RevStealer is a Windows information stealer distributed through trojanized Electron applications hosted on GitHub repositories and game-cheat-themed websites.
Because most of those wallets are built with the Electron framework, ProManager reads the wallet window's saved position and opens attacker-supplied content sized and positioned to overlay the real wallet, without touching the wallet program itself.
organisation
GitHub
RevStealer is a Windows information stealer distributed through trojanized Electron applications hosted on GitHub repositories and game-cheat-themed websites.
organisation
Microsoft Defender
It attempts to add the user’s AppData directory to Microsoft Defender exclusions, decrypts an embedded native executable using AES-CBC, launches it with hidden windows, and deletes the temporary payload when possible.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
organisation
AES
It attempts to add the user’s AppData directory to Microsoft Defender exclusions, decrypts an embedded native executable using AES-CBC, launches it with hidden windows, and deletes the temporary payload when possible.
organisation
RevStealer
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
RevStealer: Silence Is Its Greatest Weapon..
organisation
Windows Update
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
organisation
Microsoft Defender
Registry Run
…the machine into a reverse proxy that routes the attacker's network traffic through the victim's connection
Logon script, scheduled task, or Registry Run key
LockAppHost
Runs a cryptocurrency miner with administrator rights after disabling Windows Update and excluding folders from Microsoft Defender
Registry Run key or a service
LockAppHost is the most disruptive of the four.
organisation
Microsoft
Once elevated, it adds Microsoft Defender exclusions for common folders and file types, disables 5 Windows Update services, disables 11 scheduled update tasks and 2 malware removal tasks, and then hides a miner within legitimate Windows processes.
organisation
Telegram
It collects browser passwords and cookies; files from more than 50 cryptocurrency wallets and a large set of wallet browser extensions; session data from Telegram and other messaging clients; VPN and FTP configuration; the Windows Credential Manager; password managers; and selected documents.
organisation
FTP
It collects browser passwords and cookies; files from more than 50 cryptocurrency wallets and a large set of wallet browser extensions; session data from Telegram and other messaging clients; VPN and FTP configuration; the Windows Credential Manager; password managers; and selected documents.
threat_actor
Silence
RevStealer: Silence Is Its Greatest Weapon..
organisation
Elastic
What each program does, in Elastic's account:
ProManager
Steals wallet files and browser wallet extensions, displays attacker-controlled content over a wallet application's window, and logs passwords typed or pasted into fields it identifies as password or passphrase inputs
Registry Run key
WinUpdate
Watches the clipboard, replaces copied cryptocurrency addresses with the att…
organisation
Registry Run
…nd browser wallet extensions, displays attacker-controlled content over a wallet application's window, and logs passwords typed or pasted into fields it identifies as password or passphrase inputs
Registry Run key
WinUpdate
Watches the clipboard, replaces copied cryptocurrency addresses with the attacker's, and collects text that looks like a wallet recovery phrase
Scheduled task, wi…
organisation
Logon
…y phrase
Scheduled task, with a Registry Run key as fallback
SoftManager
Turns the machine into a reverse proxy that routes the attacker's network traffic through the victim's connection
Logon script, scheduled task, or Registry Run key
LockAppHost
Runs a cryptocurrency miner with administrator rights after disabling Windows Update and excluding folders from Microsoft Defende…
organisation
ProManager C2
…a43ad123fe843dd4e4e2 (SoftManager)
SHA-256:
c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 (LockAppHost)
Domain:
monitor5.roast-core85[.]click (REVSTEALER C2)
Domain:
config.hubdisplay[.]lol (ProManager C2)
Domain:
health.journal-metric[.]lol (WinUpdate C2)
Domain:
metric.gardenpark[.]click (SoftManager C2)
Gen Threat Labs first documented REVSTEALER in July.
organisation
WinUpdate C2
…a43ad123fe843dd4e4e2 (SoftManager)
SHA-256:
c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 (LockAppHost)
Domain:
monitor5.roast-core85[.]click (REVSTEALER C2)
Domain:
config.hubdisplay[.]lol (ProManager C2)
Domain:
health.journal-metric[.]lol (WinUpdate C2)
Domain:
metric.gardenpark[.]click (SoftManager C2)
Gen Threat Labs first documented REVSTEALER in July.
organisation
SHA-256
Selected indicators of compromise:
SHA-256:
adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 (REVSTEALER)
SHA-256:
13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa (ProManager)
SHA-256:
7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb (WinUpdate)
SHA-256:
14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 (SoftManager)…
organisation
Polygon
Elastic recovered the four programs from the same investigation as REVSTEALER and found that they share its build tradecraft, including the same packer, runtime function resolution, and the use of Polygon smart contracts for backup configuration.
organisation
App-Bound Encryption
To obtain credentials that Chrome protects with App-Bound Encryption, REVSTEALER launches the browser in a debugger and reads the decryption key from memory.
organisation
AuraStealer
Unpacked builds also show a verification window that asks for a random six-character code before running, a gate against automated analysis that Elastic compares to
Lumma Stealer
and AuraStealer.
organisation
YARA
Elastic has published
YARA rules
and behavior rules and a set of indicators for detection and blocking.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
RevStealer is a Windows information stealer distributed through trojanized Electron applications hosted on GitHub repositories and game-cheat-themed websites.
It attempts to add the user’s AppData directory to Microsoft Defender exclusions, decrypts an embedded native executable using AES-CBC, launches it with hidden windows, and deletes the temporary payload when possible.
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner.
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
…the machine into a reverse proxy that routes the attacker's network traffic through the victim's connection
Logon script, scheduled task, or Registry Run key
LockAppHost
Runs a cryptocurrency miner with administrator rights after disabling Windows Update and excluding folders from Microsoft Defender
Registry Run key or a service
LockAppHost is the most disruptive of the four.
To gain administrator rights, it abuses the Windows CMSTP tool, falling back to a standard elevation prompt if that fails.
Once elevated, it adds Microsoft Defender exclusions for common folders and file types, disables 5 Windows Update services, disables 11 scheduled update tasks and 2 malware removal tasks, and then hides a miner within legitimate Windows processes.
It collects browser passwords and cookies; files from more than 50 cryptocurrency wallets and a large set of wallet browser extensions; session data from Telegram and other messaging clients; VPN and FTP configuration; the Windows Credential Manager; password managers; and selected documents.
It resolves Windows functions without a normal import table and calls the kernel via indirect system calls to bypass the hooks installed by security products.
Where LockAppHost has run, responders should re-enable the Windows Update services and scheduled tasks that it turned off, remove the Microsoft Defender exclusions it added, and look for a miner hidden in a suspended instance of nslookup.exe or svchost.exe.
Intelligence Sources
The Hacker News
2026-09-06
AlienVault OTX
2026-09-04
RevStealer: Silence Is Its Greatest Weapon.
AlienVault OTX
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:18
Comprehensive Tactical Telemetry
Highly Correlated Entities
26x
organisation
Identified Entity
Electron
entity
4x
industry
Targeted Sector
Finance
sector
4x
timeline
Temporal Reference
September 2
date
3x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
Contextual Telemetry
Context Block
13 METRICS
infrastructure
Affected Product
Windows
software
threat actor
APT Group
Silence
actor
general metric
Bit
64
bit
general metric
Supposed Application
5
supposed application
target region
Target Country
Russian Federation
country
target region
Target Region
CENTRAL_ASIA
region
general metric
Sandbox Checks
10
sandbox checks
general metric
Scheduled Update Tasks
11
scheduled update tasks
general metric
Removal Tasks
2
removal tasks
general metric
Cryptocurrency Wallets
50
cryptocurrency wallets
malware
Malware Payload
Lumma Stealer
tool
general metric
Youtube Channels
17
youtube channels
general metric
Samples
4,700
samples
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.