A financially motivated threat actor known as REF1695 has been running a long-term malware campaign since late 2023, using fake software installers to deploy remote access trojans and Monero miners.
This operation leverages sophisticated evasion techniques and social engineering to infect systems and generate multiple streams of revenue quietly.
Sophisticated Infection Chains and Evasion Tactics
The threat actors distribute their malware primarily through malicious ISO image files that serve as fake software installer packages.
When a victim opens the ISO, they typically find a single-stage loader and a text file containing social engineering lures.
The text file tricks users into bypassing Microsoft Defender SmartScreen warnings by claiming the software was created by a small non-profit team that cannot afford the cost of code-signing certificates.
Once the user executes the loader, it registers broad exclusions in Microsoft Defender to prevent the malware from being detected.

The campaign operators consistently use a combination of Themida, WinLicense, and .NET Reactor packing techniques across all their builds to obfuscate their malicious code heavily.
As the infection progresses, the initial loader drops additional payloads depending on the specific campaign version.

Financial Motives and Monetization Strategies
The REF1695 operation is highly focused on generating continuous financial returns through a combination of silent cryptocurrency mining and fraudulent affiliate marketing.
To maximize mining profitability, the malware installs a legitimate but vulnerable driver, WinRing0x64.sys, which grants the miner direct hardware access to optimize the processor for Monero mining.

The malware also turns off Windows sleep and hibernation, ensuring the compromised machines remain awake and mining around the clock.
Security researchers tracking the campaign have monitored public Monero mining pool dashboards and identified four active wallets controlled by the attackers.
These wallets have received a combined payout of over 27 Monero, demonstrating that low-and-slow cryptojacking operations can yield consistent, significant financial returns over time.
| Filename | Associated Payload |
|---|---|
CNB-v112-zUpdt-inPmnr.exe | CNB Bot |
MyXMRmnr_Instllr_0302.exe | Custom XMRig loader |
MnrsInstllr_240126.exe, MnrsInstllr_030126.exe | Custom XMRig loader |
PM2311.exe, PM1109.exe, … | PureMiner |
Pmnr_1303_wALL.exe, Pmnr_Instllr_1303.exe, … | PureMiner |
Beyond cryptocurrency mining, the operators monetize their infections through cost-per-action fraud. During installation, the malware displays fake error dialogs or registration prompts to the user.
These interfaces direct victims to external content locker websites under the guise of unlocking a required software registration key.
To access the fake key elastic, victims are forced to complete surveys or sign up for third-party services, generating affiliate commissions for the threat actors with every successful completion.
This dual-monetization strategy allows attackers to profit immediately from fraudulent surveys while securing long-term passive income from persistent mining payloads and remote access trojans hidden on infected devices.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.