Threats & Adversaries · Cryptojacking
REF1695 runs a financially motivated campaign deploying RATs, custom XMRig loaders, and CPA fraud via fake installer packages since late 2023. Infections use.
2 sources · Apr 2
The Hacker News
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
REF1695 spreads RATs and miners since Nov 2023 via ISO lures, earning 27.88 XMR across four wallets through cryptomining and CPA fraud.
originalElastic Security Labs
Fake Installers to Monero: A Multi-Tool Mining Operation — Elastic Security Labs
Elastic Security Labs dissects a long-running operation deploying RATs, cryptominers, and CPA fraud through fake installer lures, tracking its evolution across campaigns and Monero payouts.
originalPart of the PlainSec briefing for 2026-04-02
Every edition of this story: REF1695 campaign update