Zero Day Room
Live
Regulation & compliance

REVSTEALER Leaves Four Modules to Disable Windows Security

Elastic Security Labs has identified four new programs linked to the REVSTEALER infostealer that persist after the main malware deletes itself.

Elastic Security Labs has identified four new programs linked to the REVSTEALER infostealer that persist after the main...

Elastic Security Labs documented four previously unreported programs associated with the REVSTEALER Windows information stealer on September 2. These modules remain on an infected machine after the core stealer exfiltrates data and deletes itself.

One of these programs, named LockAppHost, switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company published its findings alongside a technical white paper, naming the four components as ProManager, WinUpdate, SoftManager, and LockAppHost.

The Persistent Activity Set

Elastic recovered the four programs from the same investigation as REVSTEALER and found they share its build tradecraft. This includes the same packer, runtime function resolution, and the use of Polygon smart contracts for backup configuration. The company describes them as an "activity set" of separate executables, not plug-ins loaded into the stealer itself.

The core REVSTEALER stealer has been sold commercially since at least February 2026. It collects browser passwords and cookies, cryptocurrency wallets, gaming accounts, messaging data, and files. After reporting "complete" to its server, it deletes itself and leaves no persistence. The four newly documented programs install into the user's profile and stay there.

Elastic did not observe any of the four modules being delivered onto a live REVSTEALER host. The connection rests on shared code and investigative context rather than an observed hand-off.

Module Capabilities and Defenses

LockAppHost is the most disruptive module. It abuses the Windows CMSTP tool to gain administrator rights, falling back to a standard elevation prompt if that fails. Once raise, it adds Microsoft Defender exclusions for common folders and file types. It also disables five Windows Update services and eleven scheduled update tasks, along with two malware removal tasks. Finally, it hides a miner within legitimate Windows processes like nslookup.exe or svchost.exe. The defensive changes it makes remain after the miner is found.

ProManager targets users of desktop cryptocurrency wallets built with the Electron framework. It reads a wallet window's saved position and opens attacker-supplied content sized and positioned to overlay the real wallet. A separate part of the module records what the user types into password and passphrase fields, including values pasted from the clipboard.

REVSTEALER itself casts a wide net for data. It collects files from more than 50 cryptocurrency wallets and a large set of wallet browser extensions. It takes session data from Telegram and other messaging clients, VPN and FTP configuration, the Windows Credential Manager, password managers, and selected documents. For some gaming platforms, like Roblox, it decrypts the stored session cookie, allowing an account takeover without the password.

To obtain credentials that Chrome protects with App-Bound Encryption, REVSTEALER launches the browser in a debugger and reads the decryption key from memory. Elastic said this technique was likely adapted from the public ElevationKatz project and was also used by another stealer, VoidStealer, in March 2026. Gen Digital, which analyzed VoidStealer, described it as the first infostealer seen using the technique in the wild.

Infection Chain and Detection

REVSTEALER reaches victims mainly through game-cheat lures. Elastic identified at least 17 YouTube channels, many hijacked from their original owners, that promoted two cheat websites using short AI-generated videos. The malware has also been packaged as pirated or impersonated software, including a fake "Claude Opus 5 Free Desktop" application that copied Anthropic's branding.

The malware is built to resist analysis. It scores the machine against 10 sandbox checks and stops if the total is too high. It terminates on systems set to one of 10 languages used across Russia and Central Asia. It resolves Windows functions without a normal import table and calls the kernel via indirect system calls to bypass security product hooks. If its main command server is unreachable, it reads a backup address from a smart contract on the Polygon blockchain, a method known as EtherHiding.

Elastic's detection rule matched about 4,700 samples on VirusTotal over the past year, a count of files rather than confirmed infections. The company has published YARA rules and behavior rules for detection and blocking. The public YARA file covers the core stealer and the ProManager, SoftManager, and WinUpdate modules, but does not include a rule for LockAppHost.

Response and Compromise Indicators

Because the core stealer deletes itself, an infection can appear complete while the modules continue running. Where LockAppHost has run, responders should re-enable the Windows Update services and scheduled tasks it turned off, remove the Microsoft Defender exclusions it added, and look for a hidden miner. Since the stealer takes session cookies and the Chrome App-Bound Encryption key, affected users should change passwords and end active sessions on their accounts rather than assume a password reset is enough.

Elastic provided the following indicators of compromise for the modules and their command servers:

ComponentSHA-256 HashCommand Domain
REVSTEALERadc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4monitor5.roast-core85[.]click
ProManager13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfaconfig.hubdisplay[.]lol
WinUpdate7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcbhealth.journal-metric[.]lol
SoftManager14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2metric.gardenpark[.]click
LockAppHostc66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5-

Gen Threat Labs first documented REVSTEALER in July. Elastic's report and white paper are the fuller public account of the malware to date.

Related coverage

More from Regulation & compliance