logo

Fake Software Installers Used to Drop RATs and Monero Miners in Long-Running Malware Campaign

ID: 55c0dc25-489b-56a1-9b6d-a39149741195

STIX ID: report--55c0dc25-489b-56a1-9b6d-a39149741195

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A financially motivated threat actor (REF1695) has run a multi-variant malware campaign since at least November 2023 using fake installers to deploy RATs (e.g., CNB Bot, PureRAT, AsyncRAT, PulsarRAT) and Monero miners (PureMiner, SilentCryptoMiner, custom XMRig loader). The operation relies on packing and obfuscation (Themida, WinLicense, .NET Reactor), Microsoft Defender exclusions, scheduled tasks for C2 check-ins, RSA-signed commands, and CPA fraud, and has monetized mining profits (~27.88 XMR) while abusing trusted hosting like GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.