BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Installers Spread Cryptojacking Malware, RATs

REF1695 group spreads fake installers delivering miners, RATs, and CNB Bot using GitHub for stealth.

  • A financially motivated group, REF1695, uses fake software installers to deploy cryptocurrency miners and remote access trojans (RATs).
  • The campaign deploys a previously undocumented loader called CNB Bot and abuses a legitimate, vulnerable Windows kernel driver to boost mining performance.
  • Attackers have generated an estimated $9,392 in Monero (XMR) from these operations, according to tracked wallets.
  • The operation also uses CPA fraud on fake registration pages and leverages GitHub as a trusted content delivery network to avoid detection.

A financially motivated operation, codenamed REF1695, has been leveraging fake software installers to deploy remote access trojans and cryptocurrency miners since November 2023, according to an analysis published this week. The attackers trick victims with ISO files that contain explicit instructions to disable Microsoft Defender SmartScreen protections.

- Advertisement -

Recent attacks deliver a previously undocumented .NET implant called CNB Bot. This loader configures broad antivirus exclusions and communicates with a command-and-control server via HTTP POST requests.

Meanwhile, other campaign iterations deploy known malware like PureRAT and PureMiner. They also use a bespoke .NET-based XMRig loader that fetches its configuration from a hard-coded URL.

Consequently, the attacks abuse “WinRing0x64.sys,” a legitimate but vulnerable Windows kernel driver, to gain kernel-level hardware access. The driver, which was added to XMRig miners in late 2019, modifies CPU settings to boost mining hash rates.

Another campaign variant leads to the deployment of SilentCryptoMiner. This payload disables system sleep modes, establishes persistence, and uses the same vulnerable driver to fine-tune the CPU for mining.

- Advertisement -

Furthermore, a watchdog process ensures deleted malware and persistence mechanisms are restored. The operation has accrued approximately 27.88 XMR, worth roughly $9,392, across four monitored wallets.

Elastic researchers noted the threat actors also “abuse GitHub as a payload delivery CDN, hosting staged binaries across two identified accounts.” This technique shifts the download step to a trusted platform, reducing detection risk.

Beyond cryptomining, the group monetizes infections through Cost Per Action (CPA) fraud. Victims are directed to content locker pages under the guise of software registration.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

‘Godfather of Crypto’ Predicts Bitcoin Drop to $57K in 2026

Michael Terpin, an influential crypto investor, predicts the Bitcoin bull cycle peaked and will...

Kraken Urges US Tax Reforms After Filing 56M Forms

Kraken issued over 56 million tax forms to the IRS in 2025, with 18.5...

Harvester Deploys New Linux Backdoor in Espionage

The cyber-espionage group Harvester has deployed a new Linux variant of its GoGra backdoor...

Best Shiba Inu Buy Under $0.00001? Gains 6.5% Monthly

Shiba Inu (SHIB) has rallied 2.5% in the last 24 hours amid a wider...

Bitcoin Surging as Saylor Outpaces BlackRock; Musk Hint

Bitcoin surged nearly 30% from a low of $60,000 in early Q2 2026, approaching...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading