SecurityUnverified

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

What happened

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

Why it matters

The development may change operating conditions or market expectations around Microsoft. Further confirmation and measurable outcomes matter.

Affected entities

Microsoft · MSFTNeutral

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Claims

  • Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner Observed

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude45
Market relevance74
Entity significance94
Market breadth54
Novelty68
Urgency54
Ranking · formula rank-1.0.0
Confidence factor0.8425
Freshness factor0.9839
Breaking bonus0