A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. "Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per Action) fraud, directing victims to
โกKey InsightsAI analyzingโฆ
I
info@thehackernews.com (The Hacker News)
๐ก
Original Source
The Hacker News
https://thehackernews.com/2026/04/researchers-uncover-mining-operation.htmlTags:#security#the-hacker-news
Found this useful? Share it!
Read the Full Story
Continue reading on The Hacker News
Related Stories

๐Security
Geopolitics, AI, and Cybersecurity: Insights From RSAC 2026
about 14 hours ago

๐Security
Not Toying Around: Hasbro Attack May Take 'Weeks' to Remediate
about 15 hours ago

๐Security
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
about 16 hours ago

๐Security
Security Bosses Are All-In on AI. Here's Why
about 16 hours ago
