REF1695's ISO Trick: $9K Crypto Haul from Fake Installers and RATs
Forget flashy ransomware. This crew's quietly mined 27.88 XMR — that's $9,392 — by tricking users with ISO lures since late 2023. But the real scam? RATs and fraud on top.
Threat DigestApr 03, 20264 min read10 views
⚡ Key Takeaways
REF1695 nets $9K+ via ISO-delivered miners, RATs, and CPA fraud since 2023.𝕏
Abuses GitHub as CDN and signed WinRing0 driver for stealth and speed.𝕏
Evolving from single-trick to diversified ops — watch for cross-platform jumps.𝕏
The 60-Second TL;DR
REF1695 nets $9K+ via ISO-delivered miners, RATs, and CPA fraud since 2023.
Abuses GitHub as CDN and signed WinRing0 driver for stealth and speed.
Evolving from single-trick to diversified ops — watch for cross-platform jumps.