Skip to main content
Security

Elastic documents REVSTEALER-linked modules that disable Windows defenses

Elastic documents REVSTEALER-linked modules that disable Windows defenses Image: Primary
Elastic Security Labs documented four previously unreported programs associated with the REVSTEALER Windows information stealer. One module, LockAppHost, can add Microsoft Defender exclusions, disable Windows Update services and tasks, and hide a cryptocurrency miner in legitimate Windows processes. Elastic said the modules persist after the core stealer deletes itself. The connection is based on shared code and investigative context: Elastic did not observe the modules being delivered to a live REVSTEALER host. The stealer has been distributed through game-cheat lures and impersonated or pirated software, including a fake Claude application.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Policy Products
Policy Products

Nigeria opens antitrust probe into Uber's abrupt exit

Nigeria's antitrust commission said it is probing Uber Technologies' abrupt exit from the country after the ride-hailing platform shut down last week without prior notice to users. The supplied summary does not state why Uber exit...

Robotics
Robotics

Atoms develops robotaxi technology after Pronto acquisition

Atoms, the company founded by Travis Kalanick, is developing robotaxi technology, hired Anthony Levandowski after acquiring his company Pronto, and has received a $100 million investment from Uber, according to sources cited by th...

AI Infrastructure
AI Infrastructure

Google deploys WeatherNext 3 across consumer and cloud products

Google and DeepMind have released WeatherNext 3, an AI weather model that uses live geostationary satellite data rather than traditional physics simulations, according to the report. Google says it generates hourly forecasts at up...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...

Security AI
Security AI

Microsoft reports ASCII-smuggling use in email spam

Microsoft said email spammers are adopting ASCII smuggling, a technique used to conceal malicious instructions in AI-agent prompt-injection attacks, to evade email-platform filters. The reported shift applies the obfuscation techn...