HackerFeeds

CyberSecurity News

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News
· September 6, 2026

AI summary

Elastic Security Labs has identified four previously unknown modules linked to the REVSTEALER Windows information stealer. These modules remain on a compromised machine even after REVSTEALER removes itself. One of these modules is capable of disabling Windows Update and Microsoft Defender, and then proceeds to run a cryptocurrency miner. The four modules have been named ProManager, WinUpdate, SoftManager, and another unnamed module. They are associated with the REVSTEALER malware, which is a type of Windows information stealer. The modules' ability to disable security features allows them to operate without interruption.

Read the full article at The Hacker Newsthehackernews.com/2026/09/four-revstealer-linked-modules-disable.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.