{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/crypto-miner/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["infostealer","crypto-miner","persistence","malware"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eREVSTEALER is a commercial information stealer detected in the wild since February 2026, primarily distributed via malicious game-cheat lures and impersonated AI applications. While the core stealer exfiltrates credentials, browser data, and wallet files before self-deleting, it is often associated with four post-exploitation modules: ProManager, WinUpdate, SoftManager, and LockAppHost. These modules persist in the user profile to perform secondary malicious actions.\u003c/p\u003e\n\u003cp\u003eMost notably, LockAppHost achieves administrative persistence by abusing the CMSTP tool to disable Windows Update services and Microsoft Defender features. It subsequently deploys a cryptocurrency miner masked within system processes. These modules share tradecraft with the core stealer, including indirect system calls, packer-based obfuscation, and the use of Polygon smart contracts for resilient command-and-control communication. Organizations should prioritize detection of these persistent modules, as the primary stealer may have already completed its execution before security teams identify the compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInitial delivery of REVSTEALER via malicious game-cheat lures or impersonated software installers.\u003c/li\u003e\n\u003cli\u003eExecution of the core stealer using indirect syscalls and anti-sandbox checks to evade security analysis.\u003c/li\u003e\n\u003cli\u003eExfiltration of credentials, cookies, and sensitive session data to the primary C2 or blockchain-based backup.\u003c/li\u003e\n\u003cli\u003eDeployment of persistent secondary modules (e.g., LockAppHost) into the user profile.\u003c/li\u003e\n\u003cli\u003eElevation of privileges using CMSTP abuse to gain administrative rights.\u003c/li\u003e\n\u003cli\u003eDisabling of Windows Update services and modification of Microsoft Defender exclusions to weaken system defenses.\u003c/li\u003e\n\u003cli\u003eExecution of a hidden cryptocurrency miner within a suspended instance of legitimate processes like nslookup.exe or svchost.exe.\u003c/li\u003e\n\u003cli\u003eLong-term persistence maintained via Registry Run keys or scheduled tasks for secondary modules.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful infection results in the total loss of credentials, browser cookies, cryptocurrency wallet contents, and messaging data. The persistence modules enable long-term resource hijacking through cryptocurrency mining and proxying, while the weakened security state leaves the machine susceptible to subsequent opportunistic exploitation. Observed activity includes thousands of samples detected in the wild, indicating high-volume distribution targeting end users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eDeploy Sigma rules to monitor for unauthorized execution of cmstp.exe for privilege escalation.\u003c/li\u003e\n\u003cli\u003eHunt for persistence artifacts associated with the identified modules, specifically Registry Run keys and scheduled tasks that execute unsigned binaries in user profile directories.\u003c/li\u003e\n\u003cli\u003eMonitor for Windows Update service status changes or unusual Defender exclusion modifications.\u003c/li\u003e\n\u003cli\u003eInspect suspended processes (nslookup.exe, svchost.exe) for unexpected malicious threads or memory-resident payloads consistent with crypto-mining.\u003c/li\u003e\n\u003cli\u003eRequire password resets and session revocation for any accounts identified on compromised machines due to the theft of session cookies and browser secrets.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-06T10:42:50Z","date_published":"2026-09-06T10:42:50Z","id":"https://feed.craftedsignal.io/briefs/2026-09-revstealer-modules/","summary":"REVSTEALER is an emerging information stealer that drops modular components capable of persistence, credential theft, clipboard hijacking, and stealthy cryptocurrency mining while disabling security controls.","title":"REVSTEALER Modular Information Stealer and Persistence Modules","url":"https://feed.craftedsignal.io/briefs/2026-09-revstealer-modules/"}],"language":"en","title":"CraftedSignal Threat Feed - Crypto-Miner","version":"https://jsonfeed.org/version/1.1"}