The Crypto-Con: Unmasking the Multi-Layered “REF1695” Mining Operation
ID: 0b68ebb6-0cf6-5bbf-aa3d-b63a8e288897
STIX ID: report--0b68ebb6-0cf6-5bbf-aa3d-b63a8e288897
Feed Name: securityonline.info
Threat Score
Elastic Security Labs uncovered REF1695, a sophisticated financially motivated campaign that lures victims with fake installers to deploy a .NET RAT (CNB Bot), a custom XMRig loader and kernel components to mine Monero and monetize via CPA fraud; the operation employs strong packing/evasion (Themida/WinLicense + .NET Reactor), RSA-2048 task signing and anti-analysis techniques and has recorded payouts of approximately 27.88 XMR.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
