Elastic Security Labs Finds Persistent Modules Tied to REVSTEALER
Elastic Security Labs, the research arm of the cybersecurity company Elastic, has documented four previously unreported programs linked to REVSTEALER, an emerging Windows information stealer designed to harvest credentials, browser data, and other sensitive information from infected machines. According to Elastic Security Labs, the four programs remain installed on a compromised computer even after REVSTEALER itself deletes its own files, giving attackers a foothold that survives the initial infection.
One of the four programs, cataloged alongside names such as ProManager, WinUpdate, and SoftManager, disables Windows Update and Microsoft Defender, the antivirus and threat protection component built into Windows, before launching a cryptocurrency miner on the infected machine. Cryptocurrency mining malware, often called cryptojacking software, uses a victim's processor or graphics card to generate digital currency for the attacker without the owner's knowledge, typically degrading system performance and increasing electricity costs. Elastic Security Labs has not disclosed the identity of the fourth module in the initial disclosure covered here.
The report, published as REVSTEALER continues to circulate among Windows users, matters because it shows a shift from a single purpose credential stealer to a multi stage toolkit that keeps working long after the original stealer is gone.
Key Takeaway
REVSTEALER's companion modules are built to survive after the stealer removes itself, and at least one disables Windows Update and Microsoft Defender before mining cryptocurrency. If a machine has ever run REVSTEALER, assume it may still be compromised even after the original stealer process is gone.
Why Self Deleting Stealers With Persistent Payloads Are Harder to Catch
Traditional advice tells users to run an antivirus scan after a suspected infection and move on once the scan comes back clean. REVSTEALER's design complicates that response. Because the stealer deletes itself after harvesting data, a scan run after the fact may find nothing tied to the original infection while separate, renamed modules such as ProManager, WinUpdate, or SoftManager continue running in the background. Disguising these components with generic, IT sounding names is a common technique to blend into a list of running processes or scheduled tasks that a non specialist would not think to question.
Disabling Windows Update and Microsoft Defender before mining cryptocurrency is a deliberate sequencing choice. Microsoft Defender can detect and quarantine known miner binaries and behavioral patterns associated with unauthorized mining, so turning it off first removes the most likely automated defense on a default Windows installation. Blocking Windows Update prevents the operating system from receiving security patches that could close the gap the malware used to get in, or from reinstating protections the malware disabled.
Who Should Be Concerned
This threat is most relevant to organizations that rely on standard Windows endpoint defenses without additional monitoring, including small healthcare practices, tax and accounting firms, and small businesses that manage their own IT. These environments often depend on Microsoft Defender as the sole line of defense and may not have centralized logging that would flag Windows Update or Defender being silently turned off. A cryptocurrency miner running unnoticed on a practice management workstation or a tax preparer's machine during filing season can also slow systems handling sensitive client and patient data, which raises both a performance problem and a data handling concern for organizations subject to HIPAA or IRS Publication 4557 safeguards.
What Readers Should Check Now
Regardless of whether REVSTEALER has been confirmed on a network, the behavior Elastic Security Labs describes points to concrete checks any organization can run this week.
- Verify Windows Update and Defender status directly: Open Windows Security and Settings on each endpoint rather than trusting a dashboard summary, since malware that disables these services can also suppress alerts about the change.
- Look for unfamiliar scheduled tasks or services named similarly to legitimate software, such as generic manager or update utilities that were not installed by IT.
- Monitor for unexplained high CPU or GPU usage, sustained fan noise, or thermal throttling on workstations, which are common physical symptoms of unauthorized cryptocurrency mining.
- Treat a REVSTEALER detection as an incident, not a cleanup task. Because companion modules can outlive the stealer, a full reimage of the affected machine is safer than deleting individual files after any confirmed infection.
- Restrict local administrative rights where possible, since disabling Windows Update and Defender typically requires elevated privileges that a standard user account should not have.
Elastic Security Labs' findings are a reminder that endpoint security in 2026 depends on more than having Microsoft Defender turned on by default. Practices and small businesses that cannot run continuous endpoint detection and response tooling should at minimum schedule periodic manual verification of core Windows security settings, since malware families like REVSTEALER are increasingly built to turn those defenses off quietly rather than to evade them outright.
See whether the service fits
Choose a security approach that fits the way you already work
Start with the outcome and scope. A good fit is clear about who it is for, what is covered, how implementation works, and what happens when the service detects a problem.
People also look for
Keep exploring Ransomware & recovery
Reduce the chance of an infection, limit its reach, and make recovery possible without improvising under pressure.
- Common question: what is ransomwareUnderstand how ransomware worksLearn how attacks begin, spread, encrypt data, and pressure victims.
- Common question: ransomware protection for small businessProtect a small business from ransomwareCoordinate endpoint detection, access control, backups, and response planning.
- Common question: 3-2-1 backup strategyBuild recoverable backupsKeep multiple protected copies and verify that important systems can actually be restored.
- Common question: ransomware recovery planUse the ransomware protection guidePlan prevention, containment, restoration, and communication before an incident.
- Common question: healthcare ransomware preventionReduce ransomware risk in healthcareProtect clinical operations, patient records, and recovery capability.



