Gbhackers Ongoing Malware Campaign Using Fake Installers to Distribute RATs and Miners
Article Content
- •The REF1695 malware campaign has been active since late 2023.
- •Fake software installers are used to deliver RATs and Monero miners.
- •The operation continues to expand its toolset while remaining largely undetected.
A financially motivated threat actor has been running a malware campaign since late 2023, utilizing fake software installers to deliver remote access trojans (RATs) and Monero cryptocurrency miners. This operation, known as REF1695, has been active for over two years and has expanded its toolset while remaining largely undetected. The attackers employ ISO-based fake installers that mimic legitimate software setup packages, tricking users into downloading them. Once executed, these installers do not deliver the promised applications but instead install malicious software. The campaign has affected a wide range of users, particularly those seeking software downloads online. The current status indicates that the operation is still ongoing, with no signs of mitigation reported. Security professionals are advised to be vigilant against these types of threats and educate users on the risks of downloading software from unverified sources.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…