REVSTEALER-Linked Modules Disable Updates, Run Crypto Miner
Elastic Security Labs has discovered four programs associated with REVSTEALER, an emerging Windows information stealer. These programs, ProManager, WinUpdate, SoftManager, and LockAppHost, remain on an infected machine after the stealer deletes itself.
LockAppHost is particularly malicious as it disables Windows Update and Microsoft Defender before running a cryptocurrency miner with administrator rights.
The four programs share code with REVSTEALER, including its packer, runtime function resolution, and Polygon smart contracts for backup configuration.
REVSTEALER itself collects browser passwords and cookies, cryptocurrency wallets, gaming accounts, messaging data, and files, then reports 'complete' to its server before deleting itself and leaving no persistence.