Hackers Use Fake Utility Downloads to Deploy ScreenConnect and Cryptominers
ID: f514d87c-b5db-54ee-a1a1-5c73efd8e9a9
STIX ID: report--f514d87c-b5db-54ee-a1a1-5c73efd8e9a9
Feed Name: GBHackers
An active cryptojacking campaign leverages SEO poisoning and AI chatbot referrals to push spoofed utility downloads that sideload malicious DLLs, install GPU miners (gminer, lolMiner, SRBMiner-MULTI), and deploy a ScreenConnect backdoor via a masqueraded Visual C++ redistributable. Operators use process hollowing into signed binaries, certificate-pinned WebSocket C2, multiple persistence mechanisms, and anti-analysis checks; Microsoft telemetry links the activity to 150+ malicious domains and several IPs. Recommended mitigations include cloud-delivered protection, EDR in block mode, network/web protection, ASR rules, SmartScreen enforcement, and user education to avoid unverified downloads and AI-provided links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
