Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
The threat actor operation REF1695 has been actively deploying fake installers since November 2023 to distribute remote access trojans (RATs) and cryptocurrency miners, enhancing their monetization strategies. In addition to cryptomining, they exploit infected systems for CPA fraud by redirecting victims to content locker pages under the pretense of software registration, illustrating a multifaceted approach to financial gain.