logo

Fake Installers to Monero: A Multi-Tool Mining Operation

ID: bf729cfb-1764-5ca8-bde9-8fb967d13cc8

STIX ID: report--bf729cfb-1764-5ca8-bde9-8fb967d13cc8

Feed Name: Elastic Security Labs

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-27

...
...

Elastic Security Labs documents a financially motivated, multi-stage malware campaign (REF1695) active since late 2023 that delivers RATs and cryptominers via Themida/.NET Reactor‑packed fake installers. The report analyzes multiple campaigns (CNB Bot, PureRAT, PureMiner, SilentCryptoMiner), C2 protocols and configs, persistence and evasion techniques (Defender exclusions, process injection, kernel driver WinRing0x64.sys, direct syscalls), GitHub-hosted payload delivery, and extracted IoCs including sample hashes, domains, and four Monero wallets with ~27.88 XMR paid out.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.