A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. "Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per Action) fraud, directing victims to
โกKey InsightsAI analyzingโฆ
I
info@thehackernews.com (The Hacker News)
๐ก
Original Source
The Hacker News
https://thehackernews.com/2026/04/researchers-uncover-mining-operation.htmlTags:#security#the-hacker-news
Found this useful? Share it!
Read the Full Story
Continue reading on The Hacker News
Related Stories

๐Security
Fraud Rockets Higher in Mobile-First Latin America
about 17 hours ago

๐Security
Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus
about 18 hours ago

๐Security
Niobium Introduces The Fog
about 18 hours ago

๐Security
Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams
about 19 hours ago
