top of page
background.jpg

​

Four New REVSTEALER-Linked Modules Disable Windows Updates and Defender

Sep 7
2 min read

Elastic Security Labs security researchers have uncovered four previously undetected secondary programs linked to the REVSTEALER information-stealer malware targeting Windows systems. It was determined that these programs persist on the system even after the primary malware deletes itself from the victim's device.


Key Details:


  • Primary Malware Function: The core REVSTEALER malware steals browser passwords, cookies, cryptocurrency wallets, gaming accounts, and messaging data, notifies its command-and-control server, and completely deletes itself from the system.


  • Secondary Modules: Although the primary software removes itself, four newly identified programs—ProManager, WinUpdate, SoftManager, and LockAppHost—settle into the victim's user profile and maintain persistence.


  • LockAppHost Module: This module exploits the Windows CMSTP utility to elevate administrative privileges. Upon securing privileges, it adds new exclusion rules to Microsoft Defender, disables Windows Update services along with scheduled tasks, and executes background cryptocurrency mining disguised behind legitimate system processes such as nslookup or svchost.


  • ProManager Module: Transforms the device into a reverse proxy server to route attacker internet traffic through the victim's network. Additionally, it targets session data from crypto wallet applications and gaming platforms.


  • Advanced Evasion Techniques: The malware family utilizes direct system calls to bypass security product detection mechanisms and retrieves fallback configuration data via Polygon smart contracts. It extracts protected Chrome browser encryption keys by inspecting the browser at the memory level.

Recommended Security Measures


The following steps should be taken to secure systems and remediate potential infections:


  • Restoring Disabled Services: Windows Update services and associated scheduled tasks that were disabled on compromised systems must be inspected and reactivated.


  • Clearing Security Exclusions: Folder and file-type exclusions added by attackers within Microsoft Defender or installed antivirus software should be reviewed, and all unrecognized exclusions removed immediately.


  • Terminating Hidden Mining and Suspicious Processes: Suspicious or suspended nslookup and svchost processes should be investigated using Task Manager and system monitoring tools to terminate unauthorized crypto-mining activities.


  • Revoking Sessions and Updating Credentials: Because the malware steals session cookies and memory keys, changing passwords alone is insufficient. All active sessions across online accounts must be revoked, followed by password updates and enabling two-factor authentication.


  • Eliminating Persistence Mechanisms: Unauthorized entries in user profile directories, startup scripts, scheduled tasks, and registry keys should be scanned and cleared, followed by a full system scan using up-to-date security software.


Some of the measures that can be taken to protect against these types of malware include:


  • Windows and security updates should be applied regularly.

  • Microsoft Defender/Antivirus exclusions should be reviewed regularly.

  • Windows Update and security services should be monitored for unauthorized disabling.

  • Suspicious processes and cryptocurrency mining activities should be monitored.

  • User profiles, startup entries, and scheduled tasks should be regularly reviewed.

  • Active user sessions on suspicious or compromised systems should be terminated.

  • Passwords and access credentials of compromised accounts should be changed.

  • MFA should be enabled for critical accounts.

  • Regular full system scans should be performed using EDR/Antivirus solutions.

  • Security events should be centrally monitored through a SIEM system.


For more detailed information, please contact our experts at info@zerosecond.ae


 
 
 

Comments


bottom of page