hacker-news · Crawled Sep 6, 2026

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

9 IoCs
Read original article ↗

AI Summary

Elastic Security Labs identified four malicious modules—ProManager, WinUpdate, SoftManager, and LockAppHost—linked to the REVSTEALER information stealer. These modules persist on infected systems after the main stealer deletes itself and perform various malicious activities, including cryptocurrency wallet theft, clipboard manipulation, reverse proxy setup, and cryptocurrency mining. LockAppHost disables Windows Update and Microsoft Defender to run a miner with elevated privileges, weakening system defenses. The modules share code and infrastructure with REVSTEALER, including use of Polygon blockchain for C2 resiliency and common packer techniques.

AI-extracted · verify before operational use

Indicators of Compromise 9 extracted

Type Value Detail
SHA-256 adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4 Details →
SHA-256 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa Details →
SHA-256 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb Details →
SHA-256 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2 Details →
SHA-256 c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5 Details →
Domain monitor5[.]roast-core85[.]click Details →
Domain config[.]hubdisplay[.]lol Details →
Domain health[.]journal-metric[.]lol Details →
Domain metric[.]gardenpark[.]click Details →