"One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner."
LockAppHost: disabling Windows Update and Microsoft Defender
Elastic Security Labs found that one of the four modules recovered from the same investigation as REVSTEALER — named LockAppHost — is the most disruptive. To gain administrator rights it abuses the Windows CMSTP tool, and if that fails it falls back to a standard elevation prompt. Once elevated, LockAppHost adds Microsoft Defender exclusions for common folders and file types, disables five Windows Update services, disables 11 scheduled update tasks and two malware removal tasks, and hides a miner inside legitimate Windows processes. The changes that weaken the machine's defenses remain even after the miner is discovered. Elastic specifically recommends responders re-enable the Windows Update services and scheduled tasks LockAppHost turns off, remove the Defender exclusions it added, and look for a miner hidden in a suspended instance of nslookup.exe or svchost.exe.
ProManager: overlay attacks on desktop cryptocurrency wallets and input capture
ProManager targets desktop cryptocurrency wallets—many of which are built on the Electron framework. Elastic reports the module reads a wallet window's saved position and opens attacker-supplied content sized and positioned to overlay the real wallet window, without modifying the wallet program itself. A separate component of ProManager records user input from password and passphrase fields, including values pasted from the clipboard. Elastic also published a ProManager C2 domain and a SHA-256 indicator for the module.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageREVSTEALER core: breadth of data theft, evasion, and distribution
Elastic describes REVSTEALER as a commercial Windows infostealer first sold at least as early as February 2026, with the earliest sample appearing on VirusTotal that month. The core stealer exfiltrates browser passwords and cookies; files from more than 50 cryptocurrency wallets and many wallet browser extensions; gaming accounts; messaging session data (including Telegram); VPN and FTP configuration; the Windows Credential Manager; password managers; and selected documents. For some gaming platforms it decrypts stored Roblox session cookies to enable account takeover without the password.
The stealer uses a range of evasions: it scores the host against 10 sandbox checks and will stop if the total is too high, terminates on systems set to any of 10 languages used across Russia and Central Asia, resolves Windows functions without a normal import table, and calls the kernel via indirect system calls to bypass hooks from security products. If its main command server is unreachable it reads a backup address from a smart contract on the Polygon blockchain — a takedown-resistant method Elastic describes as EtherHiding. Unpacked builds include a verification window prompting for a random six-character code before running, a gate Elastic likens to mechanisms used by Lumma Stealer and AuraStealer.
Indicators, YARA coverage, and the investigative caveat
Elastic recovered four separate executables — ProManager, WinUpdate, SoftManager and LockAppHost — that share REVSTEALER build tradecraft such as the same packer, runtime function resolution, and use of Polygon smart contracts for backup configuration. The company published YARA rules and behavior rules with indicators for detection and blocking. The public YARA file covers the core stealer plus ProManager, SoftManager and WinUpdate, but does not include a rule for LockAppHost.
- REVSTEALER SHA-256: adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4
- ProManager SHA-256: 13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa
- WinUpdate SHA-256: 7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb
- SoftManager SHA-256: 14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2
- LockAppHost SHA-256: c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5
- REVSTEALER C2 domain: monitor5.roast-core85[.]click
- ProManager C2 domain: config.hubdisplay[.]lol
- WinUpdate C2 domain: health.journal-metric[.]lol
- SoftManager C2 domain: metric.gardenpark[.]click
Elastic notes an important caveat: the company did not observe any of the four modules being delivered onto a live REVSTEALER host. The connection between the core stealer and the modules rests on shared code and investigative context rather than an observed hand-off. Elastic calls the set an "activity set" and emphasizes the components are separate executables, not plug-ins loaded into the stealer.
What this means for end users, security teams, and cryptocurrency wallet users
End users: Elastic recommends avoiding downloads of "free" or unofficial versions of paid AI tools and game cheats, and installing Claude only from Anthropic's official channels. Because REVSTEALER steals session cookies and the Chrome App‑Bound Encryption key by launching the browser under a debugger, affected users should change passwords and end active sessions rather than assume a password reset alone is sufficient.
Security teams and incident responders: apply Elastic's YARA and behavior rules, hunt for the listed indicators, and, when LockAppHost is suspected, re-enable the five Windows Update services and the scheduled tasks it disables and remove the Defender exclusions it added. Also search for a miner hidden in suspended nslookup.exe or svchost.exe instances.
Cryptocurrency wallet users: ProManager's overlay technique and its ability to capture pasted clipboard contents and typed passphrases mean desktop wallet operators should be wary of unofficial wallet downloads and any unexpected window overlays while entering secrets.
Elastic published its findings and technical white paper on September 2; Gen Threat Labs first documented REVSTEALER in July. For the fuller technical detail and the full set of indicators, see Elastic's report and the public indicators linked below.




