Advertisement
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
Technology

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

April 2, 2026
The Hacker News
Scroll

A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per Action) fraud, directing victims to content locker pages under the guise of software registration, Elastic

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
The Hacker News
The Hacker News

Coverage and analysis from United States of America. All insights are generated by our AI narrative analysis engine.

United States of America
Bias: Unknown
Advertisement
You might also like

Explore More