BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Fake Installers Spread Cryptojacking Malware, RATs

REF1695 group spreads fake installers delivering miners, RATs, and CNB Bot using GitHub for stealth.

  • A financially motivated group, REF1695, uses fake software installers to deploy cryptocurrency miners and remote access trojans (RATs).
  • The campaign deploys a previously undocumented loader called CNB Bot and abuses a legitimate, vulnerable Windows kernel driver to boost mining performance.
  • Attackers have generated an estimated $9,392 in Monero (XMR) from these operations, according to tracked wallets.
  • The operation also uses CPA fraud on fake registration pages and leverages GitHub as a trusted content delivery network to avoid detection.

A financially motivated operation, codenamed REF1695, has been leveraging fake software installers to deploy remote access trojans and cryptocurrency miners since November 2023, according to an analysis published this week. The attackers trick victims with ISO files that contain explicit instructions to disable Microsoft Defender SmartScreen protections.

- Advertisement -

Recent attacks deliver a previously undocumented .NET implant called CNB Bot. This loader configures broad antivirus exclusions and communicates with a command-and-control server via HTTP POST requests.

Meanwhile, other campaign iterations deploy known malware like PureRAT and PureMiner. They also use a bespoke .NET-based XMRig loader that fetches its configuration from a hard-coded URL.

Consequently, the attacks abuse “WinRing0x64.sys,” a legitimate but vulnerable Windows kernel driver, to gain kernel-level hardware access. The driver, which was added to XMRig miners in late 2019, modifies CPU settings to boost mining hash rates.

Another campaign variant leads to the deployment of SilentCryptoMiner. This payload disables system sleep modes, establishes persistence, and uses the same vulnerable driver to fine-tune the CPU for mining.

- Advertisement -

Furthermore, a watchdog process ensures deleted malware and persistence mechanisms are restored. The operation has accrued approximately 27.88 XMR, worth roughly $9,392, across four monitored wallets.

Elastic researchers noted the threat actors also “abuse GitHub as a payload delivery CDN, hosting staged binaries across two identified accounts.” This technique shifts the download step to a trusted platform, reducing detection risk.

Beyond cryptomining, the group monetizes infections through Cost Per Action (CPA) fraud. Victims are directed to content locker pages under the guise of software registration.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Eyes $82K by April’s End Amid Volatility

Analysts predict a final push for Bitcoin towards the $78,000-$80,000 zone before a potential...

Worldcoin Drops 13% Despite Zoom, Docusign ID Deals

Worldcoin (WLD) dropped 13.4% to roughly $0.28 on Friday, contrasting with a broader crypto...

Bitcoin Soars Past Key Resistance; Traders See 69% Chance of $84K

Bitcoin surged 2.7%, breaking a key descending resistance line that had suppressed its price...

$650M In Shorts Liquidated Amid Bitcoin Surge

Over $800 million in crypto positions were liquidated in 24 hours as Bitcoin surged...

Tether-backed firms Northern Data and Rumble begin merger

Tether-owned companies Northern Data and Rumble have commenced their merger, giving Rumble access to...

Must Read

What Is the Dencun Upgrade for Ethereum?

The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading