logo

Hackers Use Fake Utility Downloads to Deploy ScreenConnect and Cryptominers

ID: f514d87c-b5db-54ee-a1a1-5c73efd8e9a9

STIX ID: report--f514d87c-b5db-54ee-a1a1-5c73efd8e9a9

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Mayura Kathir

...
...

An active cryptojacking campaign leverages SEO poisoning and AI chatbot referrals to push spoofed utility downloads that sideload malicious DLLs, install GPU miners (gminer, lolMiner, SRBMiner-MULTI), and deploy a ScreenConnect backdoor via a masqueraded Visual C++ redistributable. Operators use process hollowing into signed binaries, certificate-pinned WebSocket C2, multiple persistence mechanisms, and anti-analysis checks; Microsoft telemetry links the activity to 150+ malicious domains and several IPs. Recommended mitigations include cloud-delivered protection, EDR in block mode, network/web protection, ASR rules, SmartScreen enforcement, and user education to avoid unverified downloads and AI-provided links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.