AUTO-UPDATED

Microsoft warns GPU mining malware is being spread to users through SEO poisoning and AI chatbots — cryptojacking campaign targets gamers and high-end PC users with downloads disguised as popular PC utilities

Microsoft has identified an ongoing cryptojacking campaign using SEO poisoning and AI-generated recommendations to trick users into downloading GPU-mining malware disguised as popular PC utility software.

Key Points

  • Attackers impersonate legitimate tools like CrystalDiskInfo, HWMonitor, and FurMark to target users with high-performance graphics cards.
  • The malware uses DLL sideloading to execute payloads and establishes persistence by injecting code into trusted Microsoft-signed .NET utilities.
  • Malicious links have been observed appearing in AI chatbot responses, marking an emerging trend in AI-assisted search poisoning.
  • Once installed, the malware deploys ScreenConnect for remote access and runs GPU miners like lolMiner, gminer, and SRBMiner-MULTI.
  • The campaign has utilized over 150 malicious domains since March 2026 to evade detection and maintain long-term system access.

Why it Matters

This campaign demonstrates how threat actors are evolving to exploit both traditional search engines and emerging AI-assisted discovery tools to distribute malware. Users must prioritize downloading software exclusively from official vendor websites to avoid sophisticated threats that bypass standard security measures.
Tom's Hardware UK Published by Etiido Uko
Read original