Back to all news
Security

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

The Hacker News·September 6, 2026·1 min read
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs documented four new REVSTEALER-linked programs that persist after the stealer deletes itself. One disables Windows Update and Microsoft Defender before running a cryptocurrency miner. The programs are named ProManager, WinUpdate, SoftManager, and another, targeting infected Windows machines.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store