Microsoft has identified an ongoing cryptojacking campaign using SEO poisoning and AI-generated recommendations to trick users into downloading GPU-mining malware disguised as popular PC utility software.
Key Points
- Attackers impersonate legitimate tools like CrystalDiskInfo, HWMonitor, and FurMark to target users with high-performance graphics cards.
- The malware uses DLL sideloading to execute payloads and establishes persistence by injecting code into trusted Microsoft-signed .NET utilities.
- Malicious links have been observed appearing in AI chatbot responses, marking an emerging trend in AI-assisted search poisoning.
- Once installed, the malware deploys ScreenConnect for remote access and runs GPU miners like lolMiner, gminer, and SRBMiner-MULTI.
- The campaign has utilized over 150 malicious domains since March 2026 to evade detection and maintain long-term system access.