Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Overview
Researchers at Elastic Security Labs have identified four previously unknown programs connected to REVSTEALER, a Windows information-stealing malware. These programs persist on infected systems even after REVSTEALER removes itself. Notably, one of the modules disables Windows Update and Microsoft Defender, allowing a cryptocurrency miner to operate without interference. This poses a significant risk to users, as it not only compromises their data but also hijacks system resources for mining operations. Users and organizations need to be aware of these threats to protect their systems from potential exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Windows operating systems, Microsoft Defender, Windows Update
- Action Required: Users should ensure their antivirus software is up to date, disable suspicious programs, and monitor for unusual system activity.
- Timeline: Newly disclosed
Original Article Summary
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and
Impact
Windows operating systems, Microsoft Defender, Windows Update
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should ensure their antivirus software is up to date, disable suspicious programs, and monitor for unusual system activity. Regularly updating Windows and enabling security features may help mitigate risks.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Windows, Microsoft, Update, and 1 more.