Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.

One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.

The company named the four programs ProManager, WinUpdate, SoftManager, and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

CAPTCHAs have failed for 20 years

CAPTCHAs have failed for 20 years Source: Hacker News

So Reddit has decided that plain HTML is unsafe

So Reddit has decided that plain HTML is unsafe Source: Hacker News

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs

China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors