Fake Installers Spread RATs, Monero Miners in Ongoing Malware Campaign
ID: 1b8dbdea-6a8f-5366-bc3b-f01e52999103
STIX ID: report--1b8dbdea-6a8f-5366-bc3b-f01e52999103
Feed Name: GBHackers
REF1695 is a persistent malware campaign that leverages ISO-based fake installers and social engineering to deploy a toolset of RATs and cryptominers (including a novel .NET implant called CNB Bot) across multiple waves since late 2023. Operators use heavy packing (Themida/WinLicense, .NET Reactor), Microsoft Defender exclusion abuse, GitHub raw URLs for delivery, RSA-signed C2 tasking, and a custom XMRig loader with kernel driver support to maximize stealth, persistence, and Monero-based monetization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
