REVSTEALER Modules Disable Windows Defender to Run Crypto Miner

Elastic Security Labs identified four REVSTEALER-associated programs that disable Windows Update and Defender to deploy a cryptocurrency miner, persisting even after the main stealer removes itself.

Why it matters

These modules compromise endpoint defenses and consume system resources, increasing risks to enterprise infrastructure and operational stability.

SOC impact

Monitor affected endpoints for signs of disabled Windows Defender and Windows Update services. Investigate persistence mechanisms linked to the REVSTEALER modules and detect crypto mining activity. Validate the presence of these modules on hosts even after stealer removal to assess ongoing risk.

Recommended actions

  1. Identify systems with disabled Windows Defender and Windows Update
  2. Detect processes and activity linked to cryptocurrency mining
  3. Investigate artifacts related to REVSTEALER persistence modules
  4. Review endpoint telemetry for abnormal resource usage
  5. Assess the extent of infection beyond the initial stealer component

Executive Summary

Elastic Security Labs uncovered four programs linked to the REVSTEALER information stealer that actively disable critical Windows security features—namely Windows Defender and Windows Update—before deploying a cryptocurrency miner on affected machines. Notably, these modules maintain persistence even after the primary stealer deletes itself, representing a sustained threat to endpoint integrity. Operationally, this combination undermines endpoint protection capabilities and results in unauthorized use of system resources, potentially affecting organizational performance and increasing the attack surface. SOC teams should prioritize detection of these disabling behaviors and mining activity to identify and contain infections that might otherwise evade standard defenses.

SOC Impact

Monitor affected endpoints for signs of disabled Windows Defender and Windows Update services. Investigate persistence mechanisms linked to the REVSTEALER modules and detect crypto mining activity. Validate the presence of these modules on hosts even after stealer removal to assess ongoing risk.

Endpoint and Persistence Validation

  • Identify systems with disabled Windows Defender and Windows Update
  • Detect processes and activity linked to cryptocurrency mining
  • Investigate artifacts related to REVSTEALER persistence modules
  • Review endpoint telemetry for abnormal resource usage
  • Assess the extent of infection beyond the initial stealer component

Why It Matters

These modules compromise endpoint defenses and consume system resources, increasing risks to enterprise infrastructure and operational stability.

Source