REVSTEALER’s leftover modules outlast the stealer to mine crypto

Elastic finds four REVSTEALER companion modules that persist after the stealer deletes itself, including one that mines crypto.

CSBadmin
2 Min Read

Machines hit by the REVSTEALER info stealer can stay compromised long after the payload deletes itself, Elastic Security Labs reports. The stragglers install into the user’s profile instead of vanishing: Elastic named them ProManager, WinUpdate, SoftManager, and LockAppHost in a September 2 report that shipped with a technical white paper.

REVSTEALER, sold commercially since at least February 2026, sweeps browser passwords and cookies, cryptocurrency wallets, gaming accounts, messaging data, and documents before reporting back and vanishing without persistence. Shared tradecraft ties the four modules to the stealer, including the same packer, runtime function resolution, and Polygon smart contracts used for backup configuration.

LockAppHost is the most disruptive. It abuses the Windows CMSTP tool to gain administrator rights, adds Defender exclusions, disables five Windows Update services plus more than a dozen update and malware-removal tasks, then hides a cryptocurrency miner inside legitimate Windows processes. Clearing out the miner does not undo the damage: the exclusions and disabled update services stay in force, leaving the machine exposed to whatever arrives next.

The other modules widen the damage. ProManager overlays attacker-controlled content on desktop wallet windows and logs passwords typed or pasted into passphrase fields. WinUpdate watches the clipboard, swaps copied cryptocurrency addresses for the attacker’s own, and harvests text resembling wallet recovery phrases. SoftManager turns the victim’s connection into a reverse proxy that routes the attacker’s traffic.

Elastic notes it never observed the modules delivered onto a live REVSTEALER host, so the link rests on shared code and context rather than a captured hand-off. Defenders hunting these implants should audit persistence mechanisms such as Registry Run keys, scheduled tasks, logon scripts, and services, and treat any miner or wallet-overlay behavior as a sign that broader credential theft may already have occurred.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.