SECURITY·중요도 8·2026. 09. 06.·The Hacker News
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
── KO ──────────────────
REVSTEALER와 연결된 네 가지 모듈이 윈도우 업데이트와 디펜더를 비활성화합니다.
Elastic Security Labs는 REVSTEALER와 관련된 네 가지 프로그램을 문서화했습니다. 이 프로그램들은 감염된 시스템에 남아 있으며, 정보 탈취 후 스스로 삭제됩니다. 특히, 이 중 하나는 윈도우 업데이트와 마이크로소프트 디펜더를 비활성화하고 암호화폐 채굴기를 실행합니다.
── EN ──────────────────
Four modules linked to REVSTEALER disable Windows Update and Defender.
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER. These programs remain on an infected machine after the stealer deletes itself. Notably, one of the modules disables Windows Update and Microsoft Defender to run a cryptocurrency miner.