logo

Hackers Pose as Non-Profit Developers to Deploy Monero Mining Malware

ID: c4f89ee8-2f37-580f-b785-beea391e7e26

STIX ID: report--c4f89ee8-2f37-580f-b785-beea391e7e26

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive Summary:** Since late 2023, an actor identified as REF1695 has been distributing a persistent cryptomining and RAT toolkit via fake ISO installers that instruct victims to bypass security warnings; the malware uses loaders to deploy CNB Bot, PureRAT, and SilentCryptoMiner, employs a signed-like driver (WinRing0x64.sys) for high-performance Monero mining, monitors dozens of security tools to pause mining when detection is likely, and monetizes victims via mined Monero (wallets observed collecting ~27.88 XMR) and CPA fraud, while hosting components on trusted platforms and protecting control infrastructure with RSA-2048 encryption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.