Elastic Security Labs has identified four previously undocumented programs associated with REVSTEALER, a Windows information stealer that persists on infected machines after self-deletion. The programs are ProManager, WinUpdate, SoftManager, and LockAppHost, each with distinct functionalities. ProManager steals wallet files and logs passwords, WinUpdate monitors the clipboard for cryptocurrency addresses, SoftManager acts as a reverse proxy, and LockAppHost executes a cryptocurrency miner after disabling Windows Update and Microsoft Defender.
REVSTEALER has been marketed as a commercial infostealer since February 2026, exfiltrating sensitive data such as browser passwords, cookies, and cryptocurrency wallet information. It deletes itself after reporting its activities but leaves the four programs installed for persistence. These programs share build tradecraft with REVSTEALER, including the use of identical packers and runtime function resolutions.
REVSTEALER primarily spreads through game-cheat lures and disguises itself as pirated software. It employs evasion techniques to resist analysis, including checking for sandbox environments and using indirect system calls. Users are advised to avoid unofficial software and to follow specific steps if infected, such as re-enabling Windows Update services and changing passwords.
Indicators of compromise include SHA-256 hashes for REVSTEALER and its associated programs, as well as domains linked to their command and control servers.