REVSTEALER's Four Persistence Modules Disable Windows Update and Defender to Run a Hidden Miner; Infostealers Expand Into AI Agent Credential Theft
Elastic Security Labs documents four previously unreported REVSTEALER-linked executables (ProManager, WinUpdate, SoftManager, LockAppHost) that persist after the self-deleting stealer, with LockAppHost disabling Windows Update and Defender to run a concealed…
Elastic Security Labs has identified four previously unreported executables tied to REVSTEALER, a commercial Windows infostealer sold since at least February 2026: ProManager, WinUpdate, SoftManager and LockAppHost. Elastic notes none of the modules has been observed on a live host; they persist after the self-deleting stealer and share REVSTEALER tradecraft including a common packer, runtime function resolution and Polygon smart-contract backup configuration (EtherHiding). LockAppHost abuses CMSTP for elevation, adds Microsoft Defender exclusions, disables five Windows Update services and 13 scheduled tasks, and then hides a crypto miner in legitimate Windows processes; the other modules steal wallets, clipboard-swap crypto addresses and turn victims into reverse proxies. REVSTEALER also steals Chrome App-Bound Encryption keys via debugger memory reading (per ElevationKatz). Anti-analysis measures include 10 sandbox checks, a Russia/Central Asia language exit check and indirect syscalls. Elastic's detection rule matched about 4,700 VirusTotal samples over the past year, and distribution relies on more than 17 hijacked YouTube channels promoting game cheats in AI-generated videos and a fake 'Claude Opus 5 Free Desktop' desktop app. In parallel, Gen Digital research published September 9, 2026 (reported by GBHackers and Cyber Security News) shows commodity infostealers extending collection rules to local AI coding-agent data on Windows and macOS. Per-family targeting: Amatera collects data from Cline and Continue; Remus targets Claude, Cursor and OpenCode; CallbackBeaver added Claude and Cursor, with more than 5,000 samples observed in 30 days; and macOS-focused Djinn Stealer is associated with Claude, Codex, Gemini, Cline, OpenCode and Kilo. Amatera and Remus detections were recorded among tens of thousands of protected Windows users over three months (the three-month figure comes from Cyber Security News; GBHackers does not specify a timeframe) — detections, not confirmed infections. Stolen data includes access and refresh tokens, prompt histories, conversation databases and MCP configurations holding API keys, which can expose connected source-control, ticketing, database and cloud systems and enable paid API abuse, resale of account access and follow-on fraud. Remus is assessed as a Lumma Stealer variant using Ethereum-based EtherHiding C2 resolution, and the families add new agent targets via remotely managed dynamic collection rules without…
- Elastic Security Labs identified four previously unreported REVSTEALER-linked executables: ProManager, WinUpdate, SoftManager and LockAppHost; none has been observed on a live host — they persist after the self-deleting stealer.
- REVSTEALER is a commercial Windows infostealer sold since at least February 2026.
- LockAppHost abuses CMSTP for elevation, adds Microsoft Defender exclusions, disables 5 Windows Update services and 13 scheduled tasks, and hides a crypto miner in legitimate Windows processes.
- Other REVSTEALER modules steal wallets, clipboard-swap crypto addresses and turn victims into reverse proxies.
- REVSTEALER steals Chrome App-Bound Encryption keys via debugger memory reading (per ElevationKatz).
- Shared REVSTEALER tradecraft includes a common packer, runtime function resolution, 10 sandbox anti-analysis checks, a Russia/Central Asia language exit check, indirect syscalls and Polygon smart-contract backup configuration (EtherHiding).
- Elastic's detection rule matched about 4,700 VirusTotal samples over the past year.
- REVSTEALER distribution uses more than 17 hijacked YouTube channels, AI-generated game-cheat videos and a fake 'Claude Opus 5 Free Desktop' desktop app.
Coverage timelineoldest first · each row is one article
- · 10d agoFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
The Hacker News· 45
Elastic documents four persistent REVSTEALER-linked tools (ProManager, WinUpdate, SoftManager, LockAppHost); LockAppHost disables Windows Update and Defender to run a crypto miner.