$ techbeacon▋
Malware

New REVSTEALER Modules Sabotage Windows Security to Power Cryptocurrency Mining

New REVSTEALER Modules Sabotage Windows Security to Power Cryptocurrency Mining

Security researchers at Elastic Security Labs have uncovered four previously unknown components tied to the REVSTEALER malware family that linger on a victim's PC after the primary stealer program removes itself. One of the lingering modules actively disables Windows Update and Microsoft Defender, creating a window for a covert cryptocurrency miner to operate unhindered.

The team says the four modules were identified in a series of recent infections targeting Windows users in multiple regions. Unlike the main stealer, which focuses on exfiltrating credentials and personal data, these auxiliary programs are designed for persistence. They embed themselves in system directories, modify registry keys to survive reboots, and remain functional even after the original REVSTEALER payload self‑destructs.

Disabling Windows Update and the built‑in antivirus shields the miner from two of the most common defensive layers on modern Windows installations. With automatic patches blocked and real‑time scanning turned off, the malicious process can consume CPU cycles and generate crypto coins without triggering typical alerts. Analysts estimate that a single compromised machine could earn anywhere from a few dollars to several tens of dollars per month, depending on hardware and mining algorithm.

The discovery arrives amid a broader surge in hybrid threats that blend information theft with illicit mining. Over the past year, security firms have documented a rise in malware that first steals credentials or banking data, then pivots to cryptomining as a secondary revenue stream. The tactic complicates detection because traditional indicators of compromise—such as unusual network traffic to known mining pools—may be masked by the earlier data‑exfiltration phase.

Experts advise users to keep Windows Update enabled, regularly verify that Microsoft Defender or a reputable third‑party antivirus remains active, and monitor system performance for unexplained slowdowns. Organizations are urged to apply the latest security patches, employ application whitelisting, and consider endpoint detection and response solutions that can spot the subtle registry changes introduced by these modules. As researchers continue to dissect REVSTEALER's code, they expect additional evasive techniques to emerge, underscoring the need for vigilant, layered defenses against evolving Windows‑based threats.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related