Elastic Security Labs reported that the financially motivated REF1695 operation has used counterfeit software installers since November 2023 to infect victims with remote access trojans and cryptocurrency miners. Recent activity relied on fake ISO files containing a .NET Reactor-protected loader and a text file that led to deployment of a previously undocumented .NET implant called CNB Bot, which can inject additional payloads. The infection chain instructed users to bypass Microsoft Defender SmartScreen, then used PowerShell to add broad Microsoft Defender Antivirus exclusions, launch malware, and display a fake application error to mask the compromise.
Researchers linked the same actor to campaigns delivering PureRAT, PureMiner, a custom .NET-based XMRig loader, and SilentCryptoMiner, with some payloads abusing the vulnerable signed drivers WinRing0x64.sys and Winring0.sys to tune CPU settings and improve mining performance. The operation also used watchdog functions and scheduled tasks for persistence and recovery, communicated with command-and-control servers over HTTP POST, and abused GitHub as a trusted platform for staged payload delivery to reduce detection. Elastic estimated the campaign generated 27.88 XMR across four tracked wallets, worth about $9,392.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Elastic Security Labs published research detailing REF1695's long-running installer-based malware operation, its use of watchdogs and scheduled tasks for persistence, HTTP POST command-and-control, abuse of vulnerable WinRing0 drivers to optimize mining, and estimated earnings of 27.88 XMR across four tracked wallets. The disclosure tied together the campaign's RAT, miner, and fraud activity under a single tracked cluster.
Researchers identified a newer infection chain in which fake ISO files delivered a .NET Reactor-protected loader and supporting files that led to deployment of the previously undocumented .NET implant CNB Bot. The loader instructed users to bypass Microsoft Defender SmartScreen, used PowerShell to add broad Defender exclusions, and then launched malware while displaying a fake application error.
During the campaign, the actor used ISO files to deliver malware families including PureRAT, PureMiner, a custom .NET-based XMRig loader, and SilentCryptoMiner. Researchers also linked the operation to abuse of GitHub accounts as a trusted payload delivery platform to stage binaries and reduce detection friction.
Elastic Security Labs said the financially motivated REF1695 operation has been active since November 2023, using fake software installers to infect victims with remote access trojans and cryptocurrency miners. The campaign monetizes infections through cryptomining and CPA fraud.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.