BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Installers Spread Cryptojacking Malware, RATs

REF1695 group spreads fake installers delivering miners, RATs, and CNB Bot using GitHub for stealth.

  • A financially motivated group, REF1695, uses fake software installers to deploy cryptocurrency miners and remote access trojans (RATs).
  • The campaign deploys a previously undocumented loader called CNB Bot and abuses a legitimate, vulnerable Windows kernel driver to boost mining performance.
  • Attackers have generated an estimated $9,392 in Monero (XMR) from these operations, according to tracked wallets.
  • The operation also uses CPA fraud on fake registration pages and leverages GitHub as a trusted content delivery network to avoid detection.

A financially motivated operation, codenamed REF1695, has been leveraging fake software installers to deploy remote access trojans and cryptocurrency miners since November 2023, according to an analysis published this week. The attackers trick victims with ISO files that contain explicit instructions to disable Microsoft Defender SmartScreen protections.

- Advertisement -

Recent attacks deliver a previously undocumented .NET implant called CNB Bot. This loader configures broad antivirus exclusions and communicates with a command-and-control server via HTTP POST requests.

Meanwhile, other campaign iterations deploy known malware like PureRAT and PureMiner. They also use a bespoke .NET-based XMRig loader that fetches its configuration from a hard-coded URL.

Consequently, the attacks abuse “WinRing0x64.sys,” a legitimate but vulnerable Windows kernel driver, to gain kernel-level hardware access. The driver, which was added to XMRig miners in late 2019, modifies CPU settings to boost mining hash rates.

Another campaign variant leads to the deployment of SilentCryptoMiner. This payload disables system sleep modes, establishes persistence, and uses the same vulnerable driver to fine-tune the CPU for mining.

- Advertisement -

Furthermore, a watchdog process ensures deleted malware and persistence mechanisms are restored. The operation has accrued approximately 27.88 XMR, worth roughly $9,392, across four monitored wallets.

Elastic researchers noted the threat actors also “abuse GitHub as a payload delivery CDN, hosting staged binaries across two identified accounts.” This technique shifts the download step to a trusted platform, reducing detection risk.

Beyond cryptomining, the group monetizes infections through Cost Per Action (CPA) fraud. Victims are directed to content locker pages under the guise of software registration.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump Crypto Project Rated Among Industry’s Riskiest

The newly launched ratings firm CORE3 has assigned a 'DDD' risk grade to the...

U.S. Crypto Clarity Act Nears Key Senate Deal

Coinbase Chief Legal Officer Paul Grewal announced lawmakers are nearing a resolution on disputed...

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading