Illustrative image generated with AI
REVSTEALER-Linked Windows Malware Persists to Steal Crypto, Relay Traffic, and Mine Coins
Elastic links four persistent Windows executables to REVSTEALER that steal crypto wallets, hijack clipboards, proxy traffic, and mine coins.
Text generated by artificial intelligence, published without human review. AI transparency
Elastic Security Labs has uncovered four previously undocumented Windows executables associated with REVSTEALER, a commercial information stealer distributed largely through game cheats and counterfeit software.
The programs—ProManager, WinUpdate, SoftManager, and LockAppHost—extend the operation beyond REVSTEALER’s initial theft. They install within the user profile and establish persistence, allowing malicious activity to continue after the core stealer deletes its files.
LockAppHost presents the greatest operational risk. It elevates privileges, deploys a cryptocurrency miner, weakens Microsoft Defender, and disables Windows Update components. Those security changes can remain after responders find and remove the miner.
Elastic published its findings and a technical white paper on September 2. Gen Threat Labs first documented REVSTEALER in July, while the earliest known sample appeared on VirusTotal in February 2026.
Four persistent executables expand the initial compromise
REVSTEALER itself is designed for rapid collection and exfiltration. It steals browser passwords and cookies, Windows Credential Manager records, password-manager data, selected documents, messaging sessions, VPN and FTP configurations, gaming credentials, and data linked to more than 50 cryptocurrency wallets.
Once collection finishes, the malware reports to its command server and removes itself. This lack of persistence can create a false impression that the compromise has ended.
The four related executables behave differently:
- ProManager targets desktop cryptocurrency wallets through credential capture and deceptive window overlays.
- WinUpdate manipulates clipboard contents and collects wallet recovery phrases.
- SoftManager turns the computer into a reverse proxy for attacker-controlled traffic.
- LockAppHost establishes an elevated cryptocurrency miner while degrading Windows security and update functions.
These are independent executables, not plug-ins loaded inside REVSTEALER. Elastic recovered them during the same investigation and linked them through common development traits, including a shared packer, dynamic Windows API resolution, and Polygon smart contracts used for fallback configuration.
However, researchers did not directly observe any of the four files being delivered to an active REVSTEALER infection. The attribution is consequently based on code similarities and investigative context rather than a confirmed execution chain.
REVSTEALER can launch additional command-line programs, which provides a technically plausible route for deploying the components. Whether that mechanism is used for these specific modules is not known.
Wallet overlays and clipboard theft target cryptocurrency users
ProManager exploits a common characteristic of desktop cryptocurrency wallets: many are built with the Electron framework and store details about their window position and dimensions.
The malware reads those saved coordinates, then places attacker-controlled content directly over the legitimate wallet window. Because the overlay is aligned with the authentic application, victims may believe they are interacting with their wallet rather than a malicious interface.
ProManager monitors fields classified as password or passphrase inputs. It captures secrets entered manually and values pasted from the clipboard, covering both conventional passwords and longer wallet credentials. It can restart at logon through a Registry Run key.
WinUpdate attacks a different part of cryptocurrency transactions. It watches the Windows clipboard for copied wallet addresses and substitutes an address controlled by the attacker. If the victim does not compare the full destination before approving a transfer, funds may be sent irreversibly to the wrong wallet.
The module also looks for text matching the expected format of a wallet recovery phrase. Such phrases can provide complete control over a wallet, making their theft potentially more damaging than the loss of an individual account password.
WinUpdate persists primarily through a scheduled task, with a Registry Run key serving as an alternative mechanism.
LockAppHost leaves Windows defenses disabled
LockAppHost attempts to gain administrator privileges by abusing CMSTP, a legitimate Windows utility associated with Connection Manager profiles. If that technique does not work, the malware falls back to a standard elevation prompt.
After obtaining elevated access, it makes extensive defensive changes:
- Adds Microsoft Defender exclusions covering commonly used directories and file types.
- Disables five Windows Update services.
- Disables 11 scheduled tasks associated with updates.
- Disables two malware-removal tasks.
- Hides its cryptocurrency miner inside legitimate Windows processes.
The component can maintain persistence through either a Registry Run key or a Windows service. Elastic advises responders to search specifically for a miner concealed in suspended instances of nslookup.exe or svchost.exe.
Removing the mining payload is not enough. The Defender exclusions and disabled maintenance components can survive discovery of the miner, leaving the system more exposed to future malware and preventing normal security updates.
SoftManager creates a separate category of risk. It establishes a reverse proxy that lets attackers send network traffic through the victim’s connection. This consumes bandwidth while associating potentially malicious activity with the victim’s public IP address and network reputation.
SoftManager supports three persistence options: a logon script, a scheduled task, or a Registry Run key.
Stolen cookies can bypass a password reset
REVSTEALER’s browser capabilities go beyond reading stored passwords. For Roblox accounts, it decrypts the saved session cookie, potentially allowing account takeover without the attacker knowing the password.
The malware can also defeat Chrome’s App-Bound Encryption protection by launching the browser under a debugger and extracting the relevant decryption key from memory. Elastic assessed that this implementation was probably adapted from the public ElevationKatz project.
VoidStealer used the same approach in March 2026. Gen Digital, which examined that campaign, described it as the first infostealer observed applying the method in active attacks.
This capability changes the appropriate response. A password reset may not invalidate an already stolen session token. Victims should change exposed credentials and explicitly terminate all active sessions across affected browser, cryptocurrency, gaming, messaging, and password-manager accounts.
Wallet recovery phrases require an even stronger response. If a phrase may have been collected, users should treat the corresponding wallet as compromised and move assets using a trusted, clean device.
Game cheats and fake AI software provide initial access
REVSTEALER is primarily promoted through game-cheat lures. Elastic identified at least 17 YouTube channels advertising two cheat websites through short, AI-generated videos. Many of those channels had apparently been hijacked from their original owners.
The malware has also appeared inside pirated or impersonated software. Morphisec documented a fake application named “Claude Opus 5 Free Desktop” on August 31. It copied Anthropic’s branding, but there was no indication that Anthropic’s systems or legitimate software were compromised.
Users should obtain Claude through Anthropic’s official distribution channels. Unofficial offers for free versions of paid AI services, pirated applications, and game cheats carry a heightened risk of credential theft.
Elastic’s detection rule matched approximately 4,700 VirusTotal samples during the past year. That number reflects files detected by the rule, not 4,700 verified victims or installations.
REVSTEALER also checks ten sandbox indicators and exits when the cumulative score suggests an analysis environment. It refuses to operate on systems configured with any of ten languages associated with Russia and Central Asia, resolves Windows functions without a normal import table, and uses indirect system calls to reduce exposure to security hooks.
If its primary command-and-control server is unavailable, the malware can retrieve a fallback address from a smart contract on the Polygon blockchain. This EtherHiding-style design makes configuration harder to remove through conventional domain takedowns.
Indicators and response priorities
Defenders can block and investigate the following command-and-control domains:
monitor5.roast-core85[.]click
config.hubdisplay[.]lol
health.journal-metric[.]lol
metric.gardenpark[.]click
The known SHA-256 hashes are:
REVSTEALER:
adc4aa652965396b52e79435ca54987ae9eb21bf5e67de5e9461b09655165ee4
ProManager:
13d7237d7289e67c2d806a65d52580b453ce4987acbe2c4c4d04833f55ebccfa
WinUpdate:
7c08cf409194056a8517865e5d3433d1499bb8262263b55b49b8b07d9d182fcb
SoftManager:
14b2ac356ed75d10ef40bbaaa48e7dd9fff7de9719c2a43ad123fe843dd4e4e2
LockAppHost:
c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5
Elastic has released YARA and behavioral detections. Its public YARA set covers REVSTEALER, ProManager, WinUpdate, and SoftManager, but not LockAppHost, requiring behavioral hunting for the most disruptive component.
Incident responders should inspect Registry Run keys, services, scheduled tasks, and logon scripts; investigate unexpected CMSTP execution and elevation events; and look for wallet overlays, clipboard replacement, recovery-phrase collection, or unexplained proxy traffic.
On systems affected by LockAppHost, teams should restore the five disabled Windows Update services, re-enable the 11 update tasks and two malware-removal tasks, and remove unauthorized Defender exclusions. Suspended nslookup.exe and svchost.exe processes deserve immediate examination.
The central risk is persistence after apparent cleanup. Finding REVSTEALER’s self-deleting payload does not establish that the host is clean.
Sources
This article is an original reworking based on the sources below.
