Key Facts
Elastic Security Labs documented four programs associated with the REVSTEALER Windows information stealer that can remain on an infected system after the stealer removes itself.
Technical Details
Current reporting on Elastic’s research says the modules steal wallet data and credentials, proxy attacker traffic, replace copied cryptocurrency addresses, or disable Windows Update and Microsoft Defender before mining cryptocurrency.
Impact & Mitigation
Use Elastic’s published detections and indicators, investigate unauthorized Defender exclusions or disabled update services, and invalidate exposed sessions and credentials following a suspected infection.
