REF3864 is an intrusion set attributed by Elastic Security Labs for targeting Chinese-speaking regions with malicious installers for Telegram and Opera, delivering malware like GOSAR. Cybereason noted similarities in techniques such as PoolParty Variant 7, suggesting possible connections to other threat actors.