logo

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

ID: 3609be8c-fac4-5928-9ec2-5b52984d2f5b

STIX ID: report--3609be8c-fac4-5928-9ec2-5b52984d2f5b

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**REF1695** is a financially motivated campaign active since November 2023 that uses ISO-based fake installers to deploy RATs, multiple cryptocurrency miners (including SilentCryptoMiner and a bespoke XMRig loader), and a new .NET loader named CNB Bot; the actor uses PowerShell to create Defender exclusions, hosts payloads on GitHub as a trusted CDN, abuses a signed vulnerable kernel driver (WinRing0x64.sys) to increase mining performance, and maintains persistence/watchdog mechanisms — the campaign has yielded an estimated 27.88 XMR (~$9,392).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.