A new malware campaign associated with the REVSTEALER information stealing malware has been discovered using another four additional malicious programs to secretly mine cryptocurrency, steal cryptocurrency data, and maintain access to compromised Windows systems.
About the malware
As per Elastic Security Labs, the four programs are called LockAppHost, SoftManager, WinUpdate, and ProManager.
Experts found that the components can stay on a computer even when REVSTEALER removes itself. This makes the compromise hard to locate and stop.
“Unlike most commodity stealers, REVSTEALER seems to put more effort into validating its targets; this is evident in its cryptocurrency wallet harvester, which uses a multi-layer architecture with a discovery engine followed by a collector that applies wallet-specific extension filters to extract only relevant files,” Elastic Security Labs reported.
What does REVSTEALER do?
Available as a commercial malware since February 2026, REVSTEALER is a rising Windows information stealer. It can store browser cookies and passwords, messaging data, cryptocurrency wallet details, files from compromised systems, and gaming accounts. Once the information is stolen, the primary malware deletes itself, which results in making the computer look legitimate.
But the four newly discovered programs work distinctly as they can remain on the target's computers by installing themselves.
The four malicious programs
LockAppHost
LockAppHost is the most disruptive component, because before launching a cryptocurrency miner, it can disable Windows security.
SoftManager
SoftManger turns a compromised system into a reverse proxy. This permits threat actors to direct their network traffic via the target’s internet connection, possibly covering the tracks of the threat actor’s real location.
WinUpdate
WinUpdate surveys the Windows clipboard. The malware can replace the addresses controlled by attackers when a user copies cryptocurrency wallet addresses. This may send cryptocurrency payments to the threat actors
ProManager
Cryptocurrency wallets are the main focus of this program. ProManager can steal browser wallet extensions and wallet files. Experts also discovered that the program can show attacker-controlled content over genuine cryptocurrency wallet apps and store passphrases and passwords typed by users.
LockAppHost shuts down windows security
LockAppHost can get admin privileges to make major changes in the Windows system, Elastic found.
LockAppHost can also disable five Windows Update services, impact Microsoft Defender, turn off two malware-removal tasks, and shut down 11 scheduled update tasks. It launches a cryptocurrency miner after compromising the computer’s security features.
The miner makes it difficult to detect for users to find out malicious operations and for security software to detect by hiding inside authenticated Windows processes.