<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Crypto-Miner - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/crypto-miner/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 06 Sep 2026 10:42:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/crypto-miner/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>REVSTEALER Modular Information Stealer and Persistence Modules</title><link>https://feed.craftedsignal.io/briefs/2026-09-revstealer-modules/</link><pubDate>Sun, 06 Sep 2026 10:42:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-revstealer-modules/</guid><description>REVSTEALER is an emerging information stealer that drops modular components capable of persistence, credential theft, clipboard hijacking, and stealthy cryptocurrency mining while disabling security controls.</description><content:encoded><![CDATA[<p>REVSTEALER is a commercial information stealer detected in the wild since February 2026, primarily distributed via malicious game-cheat lures and impersonated AI applications. While the core stealer exfiltrates credentials, browser data, and wallet files before self-deleting, it is often associated with four post-exploitation modules: ProManager, WinUpdate, SoftManager, and LockAppHost. These modules persist in the user profile to perform secondary malicious actions.</p>
<p>Most notably, LockAppHost achieves administrative persistence by abusing the CMSTP tool to disable Windows Update services and Microsoft Defender features. It subsequently deploys a cryptocurrency miner masked within system processes. These modules share tradecraft with the core stealer, including indirect system calls, packer-based obfuscation, and the use of Polygon smart contracts for resilient command-and-control communication. Organizations should prioritize detection of these persistent modules, as the primary stealer may have already completed its execution before security teams identify the compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Initial delivery of REVSTEALER via malicious game-cheat lures or impersonated software installers.</li>
<li>Execution of the core stealer using indirect syscalls and anti-sandbox checks to evade security analysis.</li>
<li>Exfiltration of credentials, cookies, and sensitive session data to the primary C2 or blockchain-based backup.</li>
<li>Deployment of persistent secondary modules (e.g., LockAppHost) into the user profile.</li>
<li>Elevation of privileges using CMSTP abuse to gain administrative rights.</li>
<li>Disabling of Windows Update services and modification of Microsoft Defender exclusions to weaken system defenses.</li>
<li>Execution of a hidden cryptocurrency miner within a suspended instance of legitimate processes like nslookup.exe or svchost.exe.</li>
<li>Long-term persistence maintained via Registry Run keys or scheduled tasks for secondary modules.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful infection results in the total loss of credentials, browser cookies, cryptocurrency wallet contents, and messaging data. The persistence modules enable long-term resource hijacking through cryptocurrency mining and proxying, while the weakened security state leaves the machine susceptible to subsequent opportunistic exploitation. Observed activity includes thousands of samples detected in the wild, indicating high-volume distribution targeting end users.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Deploy Sigma rules to monitor for unauthorized execution of cmstp.exe for privilege escalation.</li>
<li>Hunt for persistence artifacts associated with the identified modules, specifically Registry Run keys and scheduled tasks that execute unsigned binaries in user profile directories.</li>
<li>Monitor for Windows Update service status changes or unusual Defender exclusion modifications.</li>
<li>Inspect suspended processes (nslookup.exe, svchost.exe) for unexpected malicious threads or memory-resident payloads consistent with crypto-mining.</li>
<li>Require password resets and session revocation for any accounts identified on compromised machines due to the theft of session cookies and browser secrets.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>infostealer</category><category>crypto-miner</category><category>persistence</category><category>malware</category></item></channel></rss>