REVSTEALER post-self-delete modules for wallet theft and mining
Malware Activity
Summary
Hide ▲
Show ▼
REVSTEALER now has four linked Windows modules that persist after self-deletion and keep stealing wallets, hijacking clipboard content, proxying traffic, and mining cryptocurrency. The added modules extend the infection beyond the original stealer and can leave a host active even after the main payload appears gone. One module targets wallet users, another rewrites copied crypto addresses, a third relays attacker traffic through the victim machine, and a fourth disables Windows Update and Microsoft Defender before launching a miner. The broader package is also distributed through game-cheat lures and impersonated software.
Related Happenings
REVSTEALER game-cheat lure campaign on hijacked YouTube channels
Campaign
H score25
First: 06.09.2026 11:34
Last: 06.09.2026 11:34
Sources 1
How related:
REVSTEALER reaches victims mainly through game-cheat lures. Elastic identified at least 17 YouTube channels, many of which were hijacked from their original owners, that promoted two cheat websites using short AI-generated videos.
About this happening:
The REVSTEALER distribution campaign is still reaching new victims through game-cheat lures, widening exposure across at least 17 hijacked YouTube channels and two che...
REVSTEALER game-cheat lure campaign on hijacked YouTube channels
CampaignHow related: REVSTEALER reaches victims mainly through game-cheat lures. Elastic identified at least 17 YouTube channels, many of which were hijacked from their original owners, that promoted two cheat websites using short AI-generated videos.
About this happening: The REVSTEALER distribution campaign is still reaching new victims through game-cheat lures, widening exposure across at least 17 hijacked YouTube channels and two che...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware Activity
H score29
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper malware using USB LNK worming and Tor C2
Malware ActivityAbout this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
Campaign
H score32
First: 18.06.2026 17:30
Last: 18.06.2026 17:30
Sources 1
About this happening:
A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
Windows cryptocurrency clipper campaign targeting users via USB LNK worms
CampaignAbout this happening: A Windows cryptocurrency clipper campaign is actively targeting users since February 2026, putting clipboard data, wallet addresses, and seed phrases at risk. The operatio...
GlassWorm supply-chain malware activity
Malware Activity
H score22
First: 27.05.2026 14:48
Last: 27.05.2026 14:48
Sources 1
About this happening:
The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
GlassWorm supply-chain malware activity
Malware ActivityAbout this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...
Famous Chollima PromptMink supply-chain campaign targeting Web3 developers
Campaign
H score44
First: 29.04.2026 17:43
Last: 29.04.2026 17:43
Sources 1
About this happening:
The PromptMink campaign is widening Famous Chollima's supply-chain intrusion playbook by pushing tainted npm packages into developer environments and stealing secrets....
Famous Chollima PromptMink supply-chain campaign targeting Web3 developers
CampaignAbout this happening: The PromptMink campaign is widening Famous Chollima's supply-chain intrusion playbook by pushing tainted npm packages into developer environments and stealing secrets....
Timeline
-
06.09.2026 11:34 2 articles · 3h ago
Elastic documents REVSTEALER-linked modules that persist after self-deletion
Initial DisclosureElastic Security Labs documented four Windows programs associated with REVSTEALER—ProManager, WinUpdate, SoftManager, and LockAppHost—that remain on an infected machine after the stealer deletes itself. The modules can steal wallet files and browser wallet extensions, overlay attacker-controlled content on wallet windows, replace copied cryptocurrency addresses, route attacker traffic through the victim connection, and, in the case of LockAppHost, disable Windows Update and Microsoft Defender before launching a cryptocurrency miner.
Show sources
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner — thehackernews.com — 06.09.2026 11:34
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner — thehackernews.com — 06.09.2026 11:34