Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Summary
Elastic Security Labs has identified four new modules linked to REVSTEALER, a Windows information stealer. These modules persist on infected systems after REVSTEALER removes itself. One module disables Windows Update and Microsoft Defender to execute a cryptocurrency miner.
IFF Assessment
FOE
This discovery indicates new malware techniques that circumvent essential security measures like Windows Update and Defender, posing a direct threat to user and system security.
Defender Context
Defenders should be aware of REVSTEALER and its associated modules, as they actively disable critical security protections to facilitate cryptomining. Monitoring for signs of disabled Windows Update and Defender, as well as unusual process activity, is crucial.