Fake Software Installers Used to Drop RATs and Monero Miners in Long-Running Malware Campaign
ID: 55c0dc25-489b-56a1-9b6d-a39149741195
STIX ID: report--55c0dc25-489b-56a1-9b6d-a39149741195
Feed Name: cybersecurityNews.com
A financially motivated threat actor (REF1695) has run a multi-variant malware campaign since at least November 2023 using fake installers to deploy RATs (e.g., CNB Bot, PureRAT, AsyncRAT, PulsarRAT) and Monero miners (PureMiner, SilentCryptoMiner, custom XMRig loader). The operation relies on packing and obfuscation (Themida, WinLicense, .NET Reactor), Microsoft Defender exclusions, scheduled tasks for C2 check-ins, RSA-signed commands, and CPA fraud, and has monetized mining profits (~27.88 XMR) while abusing trusted hosting like GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
