Threats · 166 days ago
REF1695 runs a financially motivated campaign deploying RATs, custom XMRig loaders, and CPA fraud via fake installer packages since late 2023. Infections use.
2 sources covering this story
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
REF1695 spreads RATs and miners since Nov 2023 via ISO lures, earning 27.88 XMR across four wallets through cryptomining and CPA fraud.
Fake Installers to Monero: A Multi-Tool Mining Operation — Elastic Security Labs
Elastic Security Labs dissects a long-running operation deploying RATs, cryptominers, and CPA fraud through fake installer lures, tracking its evolution across campaigns and Monero payouts.
Part of the PlainSec briefing for 2026-04-03