Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.

One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.

The company named the four programs ProManager, WinUpdate, SoftManager, and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 17.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 151.243.150.222 — 2813 requests (recent log) 144.76.19.72 — 735 requests (recent log) 89.167.35.212 — 696 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 31.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 1 requests (recent log) Mehr Live-Daten und die komplette Historie im /attacks/ Watchtower-Bereich (GoAccess Report

Attack Update: Top 5 Attack-IPs auf doode.info – 17.07.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 319 requests (recent log) 144.76.19.72 — 294 requests (recent log) 216.244.66.232 — 57 requests (recent