hacker-news · Crawled Sep 6, 2026
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
9 IoCs
Read original article ↗
AI Summary
Elastic Security Labs identified four malicious modules—ProManager, WinUpdate, SoftManager, and LockAppHost—linked to the REVSTEALER information stealer. These modules persist on infected systems after the main stealer deletes itself and perform various malicious activities, including cryptocurrency wallet theft, clipboard manipulation, reverse proxy setup, and cryptocurrency mining. LockAppHost disables Windows Update and Microsoft Defender to run a miner with elevated privileges, weakening system defenses. The modules share code and infrastructure with REVSTEALER, including use of Polygon blockchain for C2 resiliency and common packer techniques.
AI-extracted · verify before operational use
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-256 | adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 | Details → |
| SHA-256 | 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa | Details → |
| SHA-256 | 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb | Details → |
| SHA-256 | 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 | Details → |
| SHA-256 | c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 | Details → |
| Domain | monitor5[.]roast-core85[.]click | Details → |
| Domain | config[.]hubdisplay[.]lol | Details → |
| Domain | health[.]journal-metric[.]lol | Details → |
| Domain | metric[.]gardenpark[.]click | Details → |