logo

Fake Installers Spread RATs, Monero Miners in Ongoing Malware Campaign

ID: 1b8dbdea-6a8f-5366-bc3b-f01e52999103

STIX ID: report--1b8dbdea-6a8f-5366-bc3b-f01e52999103

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

REF1695 is a persistent malware campaign that leverages ISO-based fake installers and social engineering to deploy a toolset of RATs and cryptominers (including a novel .NET implant called CNB Bot) across multiple waves since late 2023. Operators use heavy packing (Themida/WinLicense, .NET Reactor), Microsoft Defender exclusion abuse, GitHub raw URLs for delivery, RSA-signed C2 tasking, and a custom XMRig loader with kernel driver support to maximize stealth, persistence, and Monero-based monetization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.