Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware
ID: c4f89ee8-2f37-580f-b785-beea391e7e26
STIX ID: report--c4f89ee8-2f37-580f-b785-beea391e7e26
Feed Name: HackRead
**Executive Summary:** Since late 2023, an actor identified as REF1695 has been distributing a persistent cryptomining and RAT toolkit via fake ISO installers that instruct victims to bypass security warnings; the malware uses loaders to deploy CNB Bot, PureRAT, and SilentCryptoMiner, employs a signed-like driver (WinRing0x64.sys) for high-performance Monero mining, monitors dozens of security tools to pause mining when detection is likely, and monetizes victims via mined Monero (wallets observed collecting ~27.88 XMR) and CPA fraud, while hosting components on trusted platforms and protecting control infrastructure with RSA-2048 encryption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
