REF1695 runs a financially motivated campaign deploying RATs, custom XMRig loaders, and CPA fraud via fake installer packages since late 2023. Infections use.
Part of the PlainSec briefing for 2026-04-03