Microsoft has identified a cryptojacking campaign that uses search engine optimization (SEO) poisoning and artificial intelligence chatbot recommendations to spread GPU mining malware. The attack specifically targets high-performance PC users, including gamers and hardware enthusiasts, by disguising malicious software as popular system utilities like CrystalDiskInfo and HWMonitor.
Security researchers uncover a new cryptojacking campaign targeting high-performance PCs through deceptive utility downloads and AI chatbot recommendations.
The malware employs DLL sideloading to load malicious dynamic-link libraries alongside legitimate software installers. Once installed, it deploys ScreenConnect for remote access and uses process hollowing to inject cryptocurrency miners into Microsoft-signed .NET utilities. This technique allows the malware to run with elevated trust while evading standard detection methods.
The malicious code dynamically downloads specific mining programs such as lolMiner, gminer, or SRBMiner-MULTI based on the victim's system specifications. It actively monitors GPU usage patterns and checks for the presence of analysis tools to avoid detection during operation. This adaptive behavior ensures the malware remains hidden while maximizing computational theft.
Security researchers note that this campaign represents a significant shift in distribution tactics by leveraging AI chatbots to recommend compromised downloads. The use of SEO poisoning further amplifies reach by placing malicious links at the top of search results for legitimate utility software. Users downloading these tools from unverified sources face immediate risk of system compromise.
Microsoft advises users to verify software integrity through official vendor channels and monitor for unusual GPU activity. System administrators should implement strict application whitelisting and disable DLL sideloading where possible. Regular updates to security software remain critical for detecting process hollowing attempts.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.