B
今週中
Windows向け情報窃取マルウェア「REVSTEALER」に関連する4つの新モジュール
📌 一言でいうと
Windows向け情報窃取マルウェア「REVSTEALER」に関連する4つの新モジュールが発見されました。これらのモジュールは、感染後にWindows UpdateやMicrosoft Defenderを無効化し、暗号資産マイナーを実行させる機能を持っています。REVSTEALER本体は実行後に自己削除されますが、これらのモジュールはユーザープロファイルに永続的に的に配置される点が特徴です。
🔍該当判定
- Windows OSを搭載したPCを社内で利用している
- Microsoft Defenderを標準のウイルス対策ソフトとして利用している
- Windows Updateによる自動更新機能を有効にして運用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
エンドポイントセキュリティ製品(EDR等)による不審なプロセスの監視、およびWindows UpdateとDefenderが意図せず無効化されていないかの確認を推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】REVSTEALER関連モジュールによるセキュリティ機能無効化について
お疲れさまです。REVSTEALERに関連する新マルウェアモジュールの挙動に関する情報共有です。
■ 概要
情報窃取マルウェア「REVSTEALER」が、感染後に「ProManager」「WinUpdate」「SoftManager」「LockAppHost」という4つのモジュールをユーザープロファイルに配置することが判明しました。一部のモジュールはWindows UpdateおよびMicrosoft Defenderを強制的に無効化し、その後に暗号資産マイナーを動作させます。
■ 影響範囲
- Windows OS
■ 対応手順
1. EDR等のログを確認し、ユーザープロファイル内での不審な実行ファイル(上記名称等)の作成がないか確認してください。
2. Windows UpdateおよびMicrosoft Defenderの設定が意図せず変更されていないか、ポリシーレベルで監視を強化してください。
3. 不審なネットワーク通信(マイニングプールへの通信等)が発生していないか確認してください。
■ 参考情報
- Elastic Security Labs ホワイトペーパー
対応優先度: 中
対応期限: 随時
お疲れさまです。REVSTEALERに関連する新マルウェアモジュールの挙動に関する情報共有です。
■ 概要
情報窃取マルウェア「REVSTEALER」が、感染後に「ProManager」「WinUpdate」「SoftManager」「LockAppHost」という4つのモジュールをユーザープロファイルに配置することが判明しました。一部のモジュールはWindows UpdateおよびMicrosoft Defenderを強制的に無効化し、その後に暗号資産マイナーを動作させます。
■ 影響範囲
- Windows OS
■ 対応手順
1. EDR等のログを確認し、ユーザープロファイル内での不審な実行ファイル(上記名称等)の作成がないか確認してください。
2. Windows UpdateおよびMicrosoft Defenderの設定が意図せず変更されていないか、ポリシーレベルで監視を強化してください。
3. 不審なネットワーク通信(マイニングプールへの通信等)が発生していないか確認してください。
■ 参考情報
- Elastic Security Labs ホワイトペーパー
対応優先度: 中
対応期限: 随時
Subject: [Intel] Security Feature Disablement by REVSTEALER-Linked Modules
Dear Team,
We are sharing technical intelligence regarding new modules associated with the REVSTEALER infostealer.
■ Overview
Four previously unreported programs (ProManager, WinUpdate, SoftManager, and LockAppHost) have been identified as part of the REVSTEALER ecosystem. Unlike the main stealer which deletes itself, these modules persist in the user profile. Specifically, one module disables Windows Update and Microsoft Defender to facilitate the execution of a cryptocurrency miner.
■ Scope
- Windows OS
■ Recommended Actions
1. Monitor endpoint logs for the creation of the aforementioned files within user profiles.
2. Audit the status of Windows Update and Microsoft Defender to ensure they have not been tampered with.
3. Check for anomalous outbound traffic associated with known cryptocurrency mining pools.
■ Reference
- Elastic Security Labs Technical White Paper
Priority: Medium
Deadline: Ongoing
Dear Team,
We are sharing technical intelligence regarding new modules associated with the REVSTEALER infostealer.
■ Overview
Four previously unreported programs (ProManager, WinUpdate, SoftManager, and LockAppHost) have been identified as part of the REVSTEALER ecosystem. Unlike the main stealer which deletes itself, these modules persist in the user profile. Specifically, one module disables Windows Update and Microsoft Defender to facilitate the execution of a cryptocurrency miner.
■ Scope
- Windows OS
■ Recommended Actions
1. Monitor endpoint logs for the creation of the aforementioned files within user profiles.
2. Audit the status of Windows Update and Microsoft Defender to ensure they have not been tampered with.
3. Check for anomalous outbound traffic associated with known cryptocurrency mining pools.
■ Reference
- Elastic Security Labs Technical White Paper
Priority: Medium
Deadline: Ongoing