REVSTEALER Leaves Miners and Defense Tampering Behind
Elastic Security Labs said on September 2 that it found four previously unreported modules linked to REVSTEALER, the Windows infostealer that self-deletes after stealing data. The modules — ProManager, WinUpdate, SoftManager, and LockAppHost — stay on the machine after the main stealer reports completion and deletes itself.
Elastic says the helpers live in the user profile and keep working separately from the stealer. One of them disables Microsoft Defender and Windows Update, then hides a crypto miner inside legitimate Windows processes; another targets desktop cryptocurrency wallets by overlaying attacker content and recording typed passphrases. That means the infection can keep monetizing the system and weakening its defenses even after the original stealer is gone.
For Windows defenders, the lasting exposure is not just stolen credentials or a removed infostealer, but companion executables that may still be present and active. If the initial stealer is cleaned but these modules remain, the machine can stay under covert control and continue generating value for the attacker.