# Elastic documents REVSTEALER-linked modules that disable Windows defenses

_Sunday, September 6, 2026 at 4:34 AM EDT · Security · Latest · Tier 2 — Notable_

![Elastic documents REVSTEALER-linked modules that disable Windows defenses — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpRcdfXd6kYnqLLWSFdzGKICUzSr90MsV2f3PXtw8VDVcT-xOP2w4HwnVzrRI4bdJqhboQMFIm9BZ393b89IOqgYx-VVmb_B8-XJCsZ9SAIymdlBpEf5ARizHvn32t8Mr9stzV6nMVcn3utUYI1xSRxhaC29QZjS-C3haNSRPfQI_eBYzXCrwn5rl18Nw/s1700-nu-rw-lo-l85-e365/rev.jpg)

Elastic Security Labs documented four previously unreported programs associated with the REVSTEALER Windows information stealer. One module, LockAppHost, can add Microsoft Defender exclusions, disable Windows Update services and tasks, and hide a cryptocurrency miner in legitimate Windows processes.

Elastic said the modules persist after the core stealer deletes itself. The connection is based on shared code and investigative context: Elastic did not observe the modules being delivered to a live REVSTEALER host. The stealer has been distributed through game-cheat lures and impersonated or pirated software, including a fake Claude application.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html)

---
Canonical: https://techandbusiness.org/newswire/5FzsBy-i3-iA-Bwxtn7dCT
Retrieved: 2026-09-06T13:28:24.518Z
Publisher: Tech & Business (techandbusiness.org)
