← All articles

REVSTEALER modules disable Windows Update and Defender to hide a crypto miner

Researchers at Elastic documented four persistent programs tied to the REVSTEALER infostealer that stay on a machine even after the stealer deletes itself. One disables Windows Update services and Microsoft Defender, adds Defender exclusions, and kills update and malware-removal tasks before hiding a cryptocurrency miner inside legitimate Windows processes. The malware also bypasses Chrome's app-bound encryption by launching the browser in a debugger to read the decryption key from memory, and steals session cookies to take over accounts without passwords. It spreads through game-cheat lures on hijacked video channels and pirated or fake application installers. Because these modules outlive the stealer, a confirmed infection warrants reimaging rather than cleanup.

Check
Treat any REVSTEALER or infostealer detection as an incident and reimage the machine, since companion modules persist after the stealer removes itself, and watch for disabled Defender and high CPU usage.
Affected
Windows users who run game cheats or pirated and fake software; the modules disable protection, mine cryptocurrency, bypass Chrome's encryption to steal cookies, and persist after the stealer deletes itself.
Fix
Restrict local administrator rights so malware cannot disable Update and Defender, block game-cheat and pirated-software sources, monitor for security-tool tampering and mining activity, and reimage confirmed infections rather than deleting individual files.