Threat Intelligence

New Malware Toolkit Disables Windows Defender and Updates to Hide a Crypto Miner

The Hacker News · 6 Sept 2026
Key Takeaway Regularly verify that Windows Update and Defender remain enabled and unmodified, since some infections leave security settings disabled long after the visible threat is removed.

Elastic Security Labs has identified four previously unreported malicious programs connected to REVSTEALER, a Windows information stealer sold commercially since early 2026. Unlike the core stealer, which deletes itself after exfiltrating browser passwords, cookies, cryptocurrency wallets and other data, these four programs, named ProManager, WinUpdate, SoftManager and LockAppHost, install themselves permanently on the victim's machine.

The most damaging of the four, LockAppHost, abuses a legitimate Windows tool to gain administrator access. Once elevated, it adds security exclusions for common folders, disables multiple Windows Update services and malware removal tasks, then hides a cryptocurrency miner inside legitimate Windows processes. Crucially, the weakened security settings remain in place even after the miner itself is detected and removed. A separate program, ProManager, targets desktop cryptocurrency wallets built on the Electron framework by overlaying fake content on top of the real wallet window to trick users.

Elastic notes these programs share code, packing techniques and infrastructure with REVSTEALER but has not directly observed them being delivered by the stealer itself, meaning the link is based on shared development practices rather than a confirmed attack chain.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.