As cited
Copy frozen at (site build).
threat intel
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs identified four previously undocumented programs linked to REVSTEALER, a Windows information stealer, that persist on infected systems after the stealer removes itself. One of these programs disables Windows Update and Microsoft Defender to deploy a cryptocurrency miner. The malware uses multiple modules to establish persistence and evade security controls.
Why it matters: Windows users running systems with REVSTEALER infections face active cryptocurrency mining and disabled security updates, requiring immediate detection and remediation to prevent continued resource loss and exposure to additional threats.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs identified four previously undocumented programs linked to REVSTEALER, a Windows information stealer, that persist on infected systems after the stealer removes itself. One of these programs disables Windows Update and Microsoft Defender to deploy a cryptocurrency miner. The malware uses multiple modules to establish persistence and evade security controls.
Why it matters: Windows users running systems with REVSTEALER infections face active cryptocurrency mining and disabled security updates, requiring immediate detection and remediation to prevent continued resource loss and exposure to additional threats.
- Source published
- First seen by Cybersecurity Tracker