BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Installers Spread Cryptojacking Malware, RATs

REF1695 group spreads fake installers delivering miners, RATs, and CNB Bot using GitHub for stealth.

  • A financially motivated group, REF1695, uses fake software installers to deploy cryptocurrency miners and remote access trojans (RATs).
  • The campaign deploys a previously undocumented loader called CNB Bot and abuses a legitimate, vulnerable Windows kernel driver to boost mining performance.
  • Attackers have generated an estimated $9,392 in Monero (XMR) from these operations, according to tracked wallets.
  • The operation also uses CPA fraud on fake registration pages and leverages GitHub as a trusted content delivery network to avoid detection.

A financially motivated operation, codenamed REF1695, has been leveraging fake software installers to deploy remote access trojans and cryptocurrency miners since November 2023, according to an analysis published this week. The attackers trick victims with ISO files that contain explicit instructions to disable Microsoft Defender SmartScreen protections.

- Advertisement -

Recent attacks deliver a previously undocumented .NET implant called CNB Bot. This loader configures broad antivirus exclusions and communicates with a command-and-control server via HTTP POST requests.

Meanwhile, other campaign iterations deploy known malware like PureRAT and PureMiner. They also use a bespoke .NET-based XMRig loader that fetches its configuration from a hard-coded URL.

Consequently, the attacks abuse “WinRing0x64.sys,” a legitimate but vulnerable Windows kernel driver, to gain kernel-level hardware access. The driver, which was added to XMRig miners in late 2019, modifies CPU settings to boost mining hash rates.

Another campaign variant leads to the deployment of SilentCryptoMiner. This payload disables system sleep modes, establishes persistence, and uses the same vulnerable driver to fine-tune the CPU for mining.

- Advertisement -

Furthermore, a watchdog process ensures deleted malware and persistence mechanisms are restored. The operation has accrued approximately 27.88 XMR, worth roughly $9,392, across four monitored wallets.

Elastic researchers noted the threat actors also “abuse GitHub as a payload delivery CDN, hosting staged binaries across two identified accounts.” This technique shifts the download step to a trusted platform, reducing detection risk.

Beyond cryptomining, the group monetizes infections through Cost Per Action (CPA) fraud. Victims are directed to content locker pages under the guise of software registration.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin ETF Outflows Hit Record as Strategy Fights mNAV

Bitcoin is poised for its steepest monthly loss since June 2022 as investors flee...

Fomo raises $75M for social crypto trading as rules ease

Fomo has raised $75 million in venture capital at a $550 million valuation, led...

Microsoft’s Edge Store Hit by Stealthy “StegoAd” Malware

Microsoft shut down a large-scale malicious extension campaign on its Edge Add-ons store, dubbed...

Wells Fargo Cuts Nvidia Target But Keeps Buy Rating

Wells Fargo's Aaron Rakers reduced NVIDIA's price target from $375 to $315 but maintains...

Aave Could Outrun Bitcoin, Gain 50x By 2030: Analyst

Bitcoin has fallen over 50% from its October all-time high as a major crypto...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading