{
  "id": 5956508,
  "title": "Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner",
  "url": "https://urgent.news/2026/09/06/four-revstealer-linked-modules-disable-windows-update-and-defender-to",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-09-06T08:34:20.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}